Harvest Time Reporting

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Harvest API reference skill, but it can affect real Harvest business data if used with a powerful account token.

Install only if you want an agent to work with your Harvest account. Use the least-privileged Harvest token available, avoid broad production access while testing, and require explicit review before any create, update, delete, invoice, payment, role, user, or company-setting action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill documents destructive DELETE operations for time entries without any caution, confirmation guidance, or recovery notes. In an agent context, omission of safety framing increases the risk of accidental irreversible data deletion by users or downstream automation.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The setup section instructs use of a bearer access token and account ID but does not warn that these are sensitive credentials that grant API access. In practice, this can lead to unsafe handling, logging, or sharing of secrets in prompts, scripts, or screenshots.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal