Back to skill

Security audit

ClickFunnels

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed ClickFunnels API integration, with appropriate warnings for credentials and write actions, though its raw API passthrough is broader than one scope statement suggests.

Before installing, understand that this skill can call ClickFunnels API endpoints through Maton for the connected account, including creating, updating, and deleting business data after confirmation. Prefer OAuth, connect only the needed ClickFunnels account, specify the connection when multiple accounts exist, and review every proposed write or webhook change carefully.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill states access is scoped to a limited set of ClickFunnels resources, but the documented `maton api` passthrough can reach additional endpoints such as teams, workspaces, fulfillments, enrollments, and images. This mismatch can cause users or downstream agents to underestimate the actual authority granted, increasing the risk of overbroad data access or unintended writes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.