Flodesk

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate Flodesk integration, but it gives an agent broad authenticated power to change subscriber and workflow data without clear approval safeguards.

Install only if you are comfortable giving the agent authenticated access to your Flodesk account through Membrane. Before any unsubscribe, segment change, workflow change, POST/PATCH/DELETE, or raw proxy request, require the agent to show the target subscriber or resource, the exact intended change, and get explicit confirmation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill advertises destructive operations like unsubscribe, remove-from-segments, and remove-from-workflow without any requirement for confirmation, preview, or explicit warning about irreversible data-impacting changes. In an agent setting, this increases the chance of unintended bulk subscriber changes or workflow disruptions caused by ambiguous prompts or automation mistakes.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal