Back to skill

Security audit

Systeme.io

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Systeme.io integration that can make account changes and create persistent automations, with explicit approval and safety guidance for those high-impact actions.

Install this only if you trust Maton and need Systeme.io account automation. Use the OAuth CLI path when possible, grant the narrowest Systeme.io access available, confirm every write/delete operation, and treat webhooks, trigger destinations, functions, and --exec watches as persistent automation that should be created only for a clearly named user-controlled destination and removed when no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata and introductory description frame the capability set as contact, tag, enrollment, membership, and subscription management, but the API reference additionally exposes webhook creation, update, and deletion. That mismatch weakens user and agent understanding of the skill's true authority and can lead to underestimating a persistent data-egress capability, especially because webhooks automatically forward future customer data to an external URL.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.