Mailerlite

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real Mailerlite integration, but it gives an agent broad authenticated power to change or delete Mailerlite business data without documented confirmation safeguards.

Install only if you are comfortable granting Membrane-mediated access to the intended Mailerlite account. Before using it, instruct the agent to list or preview records first and to ask for explicit confirmation before any delete, update, bulk, send, publish, or raw proxy request; revoke the Membrane connection when you no longer need it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises destructive capabilities such as deleting subscribers, groups, campaigns, and fields without any requirement for confirmation, warning, or safety gating. In an agentic context, this increases the risk of accidental or prompt-induced irreversible actions against real user data, especially because the same document also encourages direct execution of actions via CLI.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal