Klaviyo

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real Klaviyo integration, but it gives an agent broad authenticated ability to change marketing and customer data without clear confirmation guardrails.

Install only if you trust Membrane with Klaviyo access. Before allowing changes, ask the agent to show the exact action or API request, confirm any create/update/delete operation, use the narrowest Klaviyo permissions available, and know how to revoke the Membrane/Klaviyo connection.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs the agent to run actions and raw proxy requests against Klaviyo without clearly warning that these operations may create, update, or delete live customer and marketing data. In an agent setting, missing guardrails around mutating operations increases the risk of unintended state changes, campaign launches, profile edits, or destructive API calls based on ambiguous user prompts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal