Back to skill

Security audit

chargebee

Security checks across malware telemetry and agentic risk

Overview

This Chargebee skill is a disclosed billing-admin integration with high-impact write capability, but its controls and credential handling are purpose-aligned.

Install this only if you want an agent to administer Chargebee. Use a least-privilege Chargebee connection, specify the intended connection before writes, and require explicit confirmation for any action that changes billing, subscriptions, invoices, customers, hosted pages, or portal sessions. Be aware that the underlying passthrough can reach native Chargebee API paths, so review exact endpoints and payloads before approving changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill states that only documented API Reference endpoints are supported, but the described passthrough behavior forwards arbitrary native Chargebee paths, methods, query strings, and most headers. In a billing-admin integration, this mismatch weakens operator safeguards: an agent or user may rely on the documentation boundary while still being able to invoke undocumented or higher-risk endpoints that mutate billing state or expose additional data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.