Snapchat Marketing

Security checks across malware telemetry and agentic risk

Overview

This is a real Snapchat Marketing integration, but it gives an agent broad authenticated power to change ad campaigns without clear approval guardrails.

Install only if you trust Membrane and want agent access to Snapchat Marketing. Use a least-privileged ad account, review every create/update/delete, budget, bidding, and targeting change before it runs, and consider pinning the Membrane CLI version instead of using @latest.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly enables arbitrary proxy requests to the Snapchat Marketing API, including state-changing HTTP methods like POST, PUT, PATCH, and DELETE, but does not require confirmation or warn about destructive effects. In an agent setting, this increases the risk that a vague, mistaken, or manipulated instruction could cause unauthorized campaign changes, data corruption, or deletions through a flexible low-level interface.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal