Reachmail

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate ReachMail integration, but it gives an agent broad authenticated control over email marketing and account-management data without explicit guardrails for high-impact changes.

Install only if you trust Membrane and intend to let an agent operate your ReachMail account. Use the least-privileged ReachMail account available, consider pinning the Membrane CLI version in controlled environments, and require explicit approval before sending campaigns, deleting records, bulk-changing subscribers or lists, or changing users and roles.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill explicitly documents a generic proxy request mechanism supporting mutating HTTP methods like POST, PUT, PATCH, and DELETE without requiring confirmation or warning about state-changing operations. In an agent context, this can increase the chance of unintended destructive or high-impact actions against a live ReachMail account, especially when the model falls back to raw API calls instead of constrained prebuilt actions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal