Acymailing

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate AcyMailing integration, but it needs review because it gives an agent broad authenticated power to send email campaigns, delete marketing records, and make raw API requests without explicit approval guardrails.

Install only if you trust Membrane and intend to let the agent operate on the connected AcyMailing account. Before using it, require explicit confirmation for campaign sends, deletes, subscription changes, bulk updates, and any raw proxy request, and connect the least-privileged account suitable for the task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill advertises destructive operations such as deleting campaigns, lists, and users without any warning, confirmation guidance, or guardrails. In an agentic context, this increases the chance that a model executes irreversible actions from ambiguous or mistaken prompts, causing data loss in a live marketing system.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal