Back to skill

Security audit

Harvest Time Reporting

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Harvest API reference skill, but using it with a powerful Harvest token can affect real business data.

Install only if you want an agent to work with your Harvest account. Use the least-privileged Harvest token available, avoid testing against production data, do not paste tokens into chats or logs, and require explicit review before create, update, delete, invoice, payment, role, user, or company-setting actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documents destructive DELETE operations without any caution, confirmation guidance, or rollback limitations. In an agent context, this increases the chance of accidental or over-broad deletion of projects, tasks, clients, users, invoices, or expenses through normal use or prompt misinterpretation.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill exposes numerous endpoints for accessing and transmitting sensitive business and personal data, including users, contacts, invoices, rates, expenses, and reports, but provides no privacy, minimization, or handling guidance. In an agent workflow, this can lead to unnecessary collection, display, or transmission of confidential data to external services or logs.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.