Mailchimp

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Mailchimp integration that uses Maton OAuth/API-key access to read and manage marketing data, so users should trust the Maton gateway and approve write actions carefully.

Install this only if you trust Maton to broker access to your Mailchimp account. Before approving any write action, confirm the exact Mailchimp connection, audience, campaign, subscriber set, and intended change.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI03: Identity and Privilege Abuse
Medium
What this means

Using the skill grants access to the connected Mailchimp account through Maton, including marketing and subscriber data.

Why it was flagged

The skill requires a Maton API key and uses delegated Mailchimp OAuth access through Maton, which is expected for this integration but gives the gateway account-level authority.

Skill content
All requests require the Maton API key in the Authorization header ... Maton proxies requests to your Mailchimp data center and automatically injects your OAuth token.
Recommendation

Only install if you trust Maton for this account, use the intended connection ID when multiple accounts exist, and revoke unused OAuth connections.

#
ASI02: Tool Misuse and Exploitation
Medium
What this means

Mistaken or overbroad write requests could change campaigns, templates, automations, audiences, or subscriber records.

Why it was flagged

The skill exposes Mailchimp write capabilities that can affect business marketing resources and subscriber records, while also documenting an approval requirement for writes.

Skill content
Access is scoped to audiences, campaigns, templates, automations, reports, and manage subscribers ... All write operations require explicit user approval.
Recommendation

Review every proposed create, update, or delete action, including the target account, audience, campaign, and expected effect, before approving.

#
ASI07: Insecure Inter-Agent Communication
Medium
What this means

Subscriber lists, campaign details, reports, and other Mailchimp data may be visible to or processed by the gateway provider.

Why it was flagged

Mailchimp API requests and responses are routed through the Maton gateway rather than directly to Mailchimp.

Skill content
Base URL https://api.maton.ai/mailchimp/{native-api-path} ... Maton proxies requests to your Mailchimp data center
Recommendation

Understand Maton's data-handling terms and request only the fields and records needed for the task.

#
ASI04: Agentic Supply Chain Vulnerabilities
Low
What this means

It may be harder to confirm whether this listing is officially maintained by the service provider it relies on.

Why it was flagged

The registry metadata does not provide a source repository or homepage, which makes independent provenance verification less direct.

Skill content
Source: unknown; Homepage: none
Recommendation

Verify the publisher and Maton account setup before granting Mailchimp OAuth access.