Acelle Mail

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed ActiveCampaign integration that can read and change marketing data, but its sensitive actions match the stated purpose and include an explicit user-approval requirement.

Install only if you trust Maton with access to your ActiveCampaign account. Use the least-privileged ActiveCampaign connection available, specify the intended connection when you have multiple accounts, and confirm any create, update, delete, subscribe, unsubscribe, or webhook operation before the agent runs it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill advertises destructive and privacy-impacting capabilities such as deleting subscribers/lists, unsubscribing users, and launching campaigns without any explicit requirement for confirmation, authorization checks, or user-warning language. In an agent setting, this increases the risk of accidental bulk messaging, data loss, or unauthorized contact-management actions from ambiguous prompts.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal