Mailjet

Security checks across malware telemetry and agentic risk

Overview

This Mailjet skill is a legitimate integration, but it gives an agent broad authenticated power to send email and change or delete Mailjet data without clear confirmation safeguards.

Install only if you are comfortable granting Membrane-managed access to the intended Mailjet account. Before sending emails, deleting lists, changing contacts, or using the raw proxy, require the agent to show the exact action, target ID or name, HTTP method, endpoint, and payload, then get explicit confirmation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises destructive capabilities such as deleting contact lists without any confirmation, authorization, or 'are you sure' guidance. In an agentic setting, this increases the risk that a vague, mistaken, or prompt-injected instruction could trigger irreversible state changes in a user's Mailjet account.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal