Back to skill

Security audit

Klaviyo

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Klaviyo API helper with sensitive but disclosed, purpose-aligned marketing-data access.

Install only if you trust Maton with access to the connected Klaviyo account. Keep MATON_API_KEY secret, use a specific Maton-Connection header when multiple accounts exist, and confirm the exact resource, ID, account, and effect before any write, send, webhook, bulk subscription, suppression, or import operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The security section claims access is scoped only to a narrower set of resources, but the document later exposes additional domains such as coupons, webhooks, images, forms, reviews, universal content, and bulk subscription/import actions. This mismatch can cause users or enforcement systems to underestimate what the skill can read or modify, increasing the chance of unauthorized or unexpected high-impact actions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.