Back to skill

Security audit

SendGrid

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed SendGrid integration that uses ClawLink for API-key-backed access, with broad but documented SendGrid write capabilities and no evidence of hidden code or malicious behavior.

Install only if you trust ClawLink with a SendGrid API key and are comfortable with the connected key's permissions. Prefer a least-privilege SendGrid API key, review the live tool catalog, and require preview plus explicit confirmation before any write, especially API keys, SSO, teammates, subusers, IP allow-list changes, account provisioning, webhooks, or deletions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill metadata frames the integration as email and marketing management, but the documented toolset includes materially broader powers such as API key creation, SSO administration, teammate approval, account provisioning, subuser creation, allow-list changes, and identity/domain controls. This capability mismatch can mislead users or downstream agents into granting trust or invoking the skill for seemingly narrow tasks when it actually exposes high-impact administrative actions.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The document states that all write operations require explicit user confirmation, but elsewhere provides direct write-call examples that omit preview and confirmation steps. That inconsistency can cause an agent or operator to normalize unsafe execution patterns and perform destructive or high-impact actions without the promised guardrail.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.