Easypost

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate EasyPost integration, but it gives an agent broad authenticated ability to buy labels, request refunds, and make raw API calls without clear approval limits.

Install only if you are comfortable connecting EasyPost through Membrane. Use a least-privileged or test EasyPost account where possible, verify the Membrane CLI package before installing, and require the agent to show the exact shipment, recipient, carrier, rate, refund target, and expected account effect before any purchase, refund, creation, deletion, or raw API request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill advertises actions such as buying shipments and refunding shipments without any warning that they can create charges, alter account state, or be irreversible. In an agent setting, this increases the chance that the agent executes financially impactful operations without obtaining explicit user confirmation.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal