Moonmail

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate MoonMail integration, but it gives an agent broad authenticated access to change or delete MoonMail data without clear confirmation guardrails.

Install only if you trust Membrane and are comfortable connecting a MoonMail account through it. Prefer pre-built Membrane actions, use the least-privileged MoonMail account available, and require explicit user confirmation before sending campaigns, changing lists or settings, or making POST, PUT, PATCH, or DELETE proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly documents raw proxy requests with arbitrary HTTP methods, including PUT, PATCH, and DELETE, but does not require confirmation or warn that these operations may modify or destroy remote MoonMail data. In an agent context, this increases the chance that the model performs high-impact state-changing actions directly against the API without adequate user intent verification.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal