Back to skill

Security audit

Sequenzy Email Marketing

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Sequenzy email-marketing operator, but it gives agents broad business-impacting authority and includes instructions to send product feedback externally without explicit user consent.

Install only if you intend to let the agent operate a privileged Sequenzy account. Before use, require the agent to confirm destructive actions, live/scheduled campaign changes, team/API-key/webhook operations, and any feedback submission. Do not allow automatic product-feedback reports that include business context, identifiers, incidents, or customer information unless you review the exact text first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:68
Finding

Mandatory Unauthorized Transmission of User Context Through Product Feedback

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (30)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
Read [references/use-cases.md](references/use-cases.md) before executing anything non-trivial. The currently implemented CLI flows are:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
Read [references/use-cases.md](references/use-cases.md) before executing anything non-trivial. The currently implemented CLI flows are:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
- [references/command-reference.md](references/command-reference.md): exact command shapes, env vars, behavior, and caveats.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
86% confidence
Finding

The skill documents a hard-delete subscriber operation that accepts direct user-controlled identifiers and performs permanent deletion. In an agent context handling natural-language requests, this is dangerous because prompt confusion, identifier mix-ups, or malicious instruction injection could cause irreversible loss of customer records or consent history.

Content

Scanner excerpt · references/command-reference.md (reported line 238)May include surrounding context.

md
Behavior:

- without `--hard`, sends `PATCH /api/v1/subscribers/:email` with `{ status: "unsubscribed" }`
- with `--hard`, sends `DELETE /api/v1/subscribers/:email`
- `--external-id <id>` addresses the subscriber by customer-owned ID
- supports `--company` and `--json`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/command-reference.md (reported line 271)May include surrounding context.

md
Behavior:

- `notes list`: `GET /api/v1/subscribers/:email/notes`; `notes add`: `POST /api/v1/subscribers/:email/notes`; `notes delete`: `DELETE /api/v1/subscribers/notes/:noteId`
- `--external-id` addresses the subscriber by customer-owned ID
- MCP parity: `list_subscriber_notes`, `add_subscriber_note`, and `delete_subscriber_note`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
84% confidence
Finding

List deletion removes the list and all memberships, which can materially alter campaign audiences and automation behavior. In an agent skill, exposing this as a direct destructive action creates meaningful parameter-abuse risk if an attacker or ambiguous user prompt causes the wrong listId to be supplied.

Content

Scanner excerpt · references/command-reference.md (reported line 431)May include surrounding context.

md
- `lists create`: `POST /api/v1/lists`
- create body shape is `{ name, description, isPrivate }`
- `lists update`: `PATCH /api/v1/lists/:listId` with at least one of `--name`, `--description`, `--private`, or `--no-private`
- `lists delete`: `DELETE /api/v1/lists/:listId`; removes the list and all of its memberships, reports `removedMemberships`, and keeps the subscribers themselves
- `lists add-subscribers` and `lists import`: `POST /api/v1/lists/:listId/subscribers`
- `lists remove-subscribers`: `POST /api/v1/lists/:listId/subscribers/remove`
- add-subscribers body shape is `{ emails, duplicateStrategy, enrollInSequences, optInMode }`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
83% confidence
Finding

Deleting a tag removes it from every subscriber and can break sequence references or audience logic. Because tags are high-leverage segmentation primitives, a mistaken or manipulated delete command in an agent workflow can cause broad unintended business and messaging impact.

Content

Scanner excerpt · references/command-reference.md (reported line 457)May include surrounding context.

md
- `tags list`: `GET /api/v1/tags`; bare `sequenzy tags` without a subcommand still lists tag definitions for backwards compatibility
- `tags create`: `POST /api/v1/tags` with `{ name, color? }`
- `tags update`: `PATCH /api/v1/tags/:tagId` with `{ color }` (`--color` is required)
- `tags delete`: `DELETE /api/v1/tags/:tagId`
- tag names are normalized to lowercase with dashes, so `VIP Customer` becomes `vip-customer`
- the color defaults to `gray`; valid colors are `gray`, `red`, `orange`, `amber`, `yellow`, `lime`, `green`, `emerald`, `teal`, `cyan`, `sky`, `blue`, `indigo`, `violet`, `purple`, `fuchsia`, `pink`, and `rose`
- system tags cannot be updated or deleted

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/command-reference.md (reported line 486)May include surrounding context.

md
- `segments count`: `GET /api/v1/segments/:id/count`
- `segments create`: `POST /api/v1/segments`
- `segments update`: `PATCH /api/v1/segments/:segmentId` with at least one of `--name`, `--filters-json`, `--filters-file`, or `--join-operator and|or`
- `segments delete`: `DELETE /api/v1/segments/:segmentId`; prompts for confirmation, `--yes` skips
- update filters replace the existing filter set; `--filters-json`/`--filters-file` accept the same array or `root` object shapes as create, and missing filter IDs are filled in by the CLI
- `--filter-json` accepts either the legacy raw segment filter array or a nested filter `root` object
- `--match all|any` controls whether top-level filters are combined with `and` or `or`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Product deletion can remove commerce-linked records and impact automations or digital delivery. In an agent-driven environment, unrestricted execution of destructive operations based solely on a supplied productId increases the chance of harmful misuse or accidental removal.

Content

Scanner excerpt · references/command-reference.md (reported line 519)May include surrounding context.

md
- `products list`: `GET /api/v1/products`, optionally with `?provider=stripe|shopify|woocommerce|manual&search=...`; returns one page by default (100-per-request cap), pass `--all` to page through larger catalogs
- `products sync`: `POST /api/v1/products/sync`; queues a catalog sync (`--integration` selects one when several are connected) and returns 404 without an active integration
- `products upsert [productId]`: creates or updates API-provider products keyed by your own `productId`; supports `--title`, `--description`, `--price-cents`, `--currency`, `--image-url`, `--product-url`, `--in-stock`/`--out-of-stock`, `--provider-created-at`, and bulk `--products-json`/`--products-file` for up to 100 products; combine `--file` or `--url` with a single-product upsert to attach the deliverable in the same command
- `products delete <productId>`: `DELETE /api/v1/products/:id`
- `products attach-file --file`: `POST /api/v1/products/delivery/upload-url` for a presigned URL, PUTs the file bytes there, then `PUT /api/v1/products/:id/delivery` with `source: "upload"`
- `products attach-file --url`: `PUT /api/v1/products/:id/delivery` with `source: "url"`
- `products detach-file`: `DELETE /api/v1/products/:id/delivery`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Detaching a product file removes digital delivery for future purchase-related workflows and can silently disrupt fulfillment. Because the operation is keyed only by productId, an agent could be induced to break delivery for the wrong product through prompt or identifier confusion.

Content

Scanner excerpt · references/command-reference.md (reported line 522)May include surrounding context.

md
- `products delete <productId>`: `DELETE /api/v1/products/:id`
- `products attach-file --file`: `POST /api/v1/products/delivery/upload-url` for a presigned URL, PUTs the file bytes there, then `PUT /api/v1/products/:id/delivery` with `source: "upload"`
- `products attach-file --url`: `PUT /api/v1/products/:id/delivery` with `source: "url"`
- `products detach-file`: `DELETE /api/v1/products/:id/delivery`
- MCP equivalents: `list_products`, `upsert_products`, `delete_product`, `attach_product_file` (URL attach only), `remove_product_file`, `sync_products`

Caveats:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/command-reference.md (reported line 579)May include surrounding context.

md
- `templates render`: `GET /api/v1/templates/:id/render`; same personalization and output flags as `campaigns render` (see Campaigns)
- `templates localizations set <id> <locale>` stores caller-supplied localized content immediately; the locale must be enabled in the company's localization settings and cannot be the primary locale; provide exactly one HTML or blocks content source
- `templates localizations sync <id>` queues AI translation for selected `--locale` values, or every enabled non-primary locale when omitted
- `templates delete`: `DELETE /api/v1/templates/:id`
- MCP parity: `set_template_localization` and `sync_template_localizations`

Caveats:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/command-reference.md (reported line 639)May include surrounding context.

md
- `campaigns unschedule`: returns a scheduled campaign (and any recurrence) to an editable draft; only scheduled campaigns can be unscheduled
- `campaigns pause`: `POST /api/v1/campaigns/:id/pause`
- `campaigns resume`: `POST /api/v1/campaigns/:id/resume`
- `campaigns delete`: `DELETE /api/v1/campaigns/:id`
- `campaigns duplicate`: `POST /api/v1/campaigns/:id/duplicate`
- `campaigns resend-to-non-openers`: `POST /api/v1/campaigns/:id/resend-to-non-openers`; available 6 hours after a sent campaign finishes, creates a draft targeting the same audience plus a "didn't open this campaign" rule, and estimates the non-opener count - review the draft, then schedule it
- dashboard-aware responses include `url`, campaign review `previewUrl`, and `appUrls` when the company can be resolved

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/command-reference.md (reported line 722)May include surrounding context.

md
Behavior:

- CRUD maps to `GET/POST/PATCH/DELETE /api/v1/landing-pages[/:id]`, plus `/publish`, `/unpublish`, and `/duplicate` actions and `/api/v1/landing-pages/domain` for custom domains
- pages are created as drafts; publish only after reviewing. When `--content-json/-file` is omitted, a valid default page is generated from `--template`
- a duplicate is always a draft with its own slug, views, and conversions; without `--name` it is called "<original name> (copy)"
- custom domains require a CNAME record pointing to `pages.sequenzydns.com`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

Sequence deletion is especially sensitive because sequences control ongoing automated messaging and enrollments. In this skill's context, deleting the wrong sequence can terminate automations, orphan business workflows, and affect many subscribers, making parameter abuse by an agent materially dangerous.

Content

Scanner excerpt · references/command-reference.md (reported line 772)May include surrounding context.

md
- `sequences archive` / `unarchive` hide or restore a sequence without deleting it (MCP: `archive_sequence`, `unarchive_sequence`)
- `sequences enrollments`: `GET /api/v1/sequences/:id/enrollments`; defaults to active and waiting enrollments, filters by `--status`, `--node-id`, `--subscriber-id`, and `--email`, and exports with `--all --csv <file>`. `waitUntil` is when a waiting enrollment resumes. Get node IDs from `sequences get` or `stats --sequence` (MCP: `list_sequence_enrollments`)
- `sequences pause-enrollments` stops new entrants while existing active and waiting recipients keep moving (the sequence must be active; use `disable` to freeze current recipients too); `resume-enrollments` reopens entry (MCP: `pause_sequence_enrollments`, `resume_sequence_enrollments`)
- `sequences delete`: `DELETE /api/v1/sequences/:id`
- `sequences enroll`: `POST /api/v1/sequences/:id/enroll`
- `sequences cancel-enrollments`: `POST /api/v1/sequences/:id/enrollments/cancel`
- dashboard-aware responses include `url` on sequence records and `appUrls` on the top-level JSON when the company can be resolved

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/command-reference.md (reported line 842)May include surrounding context.

md
- `ab-tests update-variant`: `PATCH /api/v1/ab-tests/:id/variants/:variantId`
- `ab-tests create`: `POST /api/v1/ab-tests`
- `ab-tests add-variant`: `POST /api/v1/ab-tests/:id/variants`
- `ab-tests delete-variant`: `DELETE /api/v1/ab-tests/:id/variants/:variantId`
- `ab-tests delete`: `DELETE /api/v1/ab-tests/:id`

Caveats:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/command-reference.md (reported line 843)May include surrounding context.

md
- `ab-tests create`: `POST /api/v1/ab-tests`
- `ab-tests add-variant`: `POST /api/v1/ab-tests/:id/variants`
- `ab-tests delete-variant`: `DELETE /api/v1/ab-tests/:id/variants/:variantId`
- `ab-tests delete`: `DELETE /api/v1/ab-tests/:id`

Caveats:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/command-reference.md (reported line 898)May include surrounding context.

md
- `team list`: `GET /api/v1/team`; returns the owner, members, and pending or expired invitations
- `team invite`: `POST /api/v1/team/invitations` with `{ email, role, canManageBilling? }`
- `team cancel-invitation`: `DELETE /api/v1/team/invitations/:invitationId`

Caveats:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/command-reference.md (reported line 959)May include surrounding context.

md
- `webhooks list`: `GET /api/v1/webhooks`
- `webhooks create`: `POST /api/v1/webhooks` with `{ name, url, events? }`
- `webhooks update`: `PATCH /api/v1/webhooks/:id` with at least one of `--name`, `--url`, `--event`, `--enable`, or `--disable`
- `webhooks delete`: `DELETE /api/v1/webhooks/:id`; this permanently deletes the endpoint and its delivery history
- `webhooks test`: `POST /api/v1/webhooks/:id/test`
- `webhooks deliveries`: `GET /api/v1/webhooks/:id/deliveries`, optionally with `?limit=` (1-100)
- `webhooks replay`: `POST /api/v1/webhooks/:id/deliveries/:deliveryId/replay`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/command-reference.md (reported line 1016)May include surrounding context.

md
- `catalog`: `GET /api/v1/integrations/catalog`; works whether or not the provider is connected - its `connectFields` list what a provider needs, and its events are the ones sequences can trigger on
- `connect`: `POST /api/v1/integrations/connect`; covers API-key / webhook-secret providers (Polar, Paddle, Dodo, Whop, Creem, Chargebee, Clerk, PostHog, Affonso). OAuth and app-install providers (Stripe, Shopify, Supabase, GitHub, WooCommerce) connect and disconnect in the dashboard only. Reconnecting replaces stored credentials, and the response includes the webhook URL to configure at the provider
- pass secrets via environment variables instead of flags to keep them out of shell history; credentials, access tokens, and webhook secrets are never returned by read commands
- `list` / `get`: connected integrations and one integration's detail - `get` lists every event the provider emits, the tags each applies through sync rules, and which sequences trigger on it
- `activity`: `GET /api/v1/integrations/activity`; retained for 24 hours - use `--status failed` when an integration reports connected but contacts are not appearing
- `sync <id>` queues a catalog/backfill re-sync (Stripe, Polar, Paddle, Dodo, Creem, Chargebee, Whop); returns immediately, poll `integrations get` to watch `syncStatus`; fails with a conflict if a sync is already running

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to "run it first and ask questions after" authorizes an immediate irreversible campaign cancel with no confirmation step. In an agent setting, this can cause unauthorized business-impacting actions, stopping legitimate outbound communications and creating operational, financial, and reputational damage from a mistaken or manipulated request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill activation description is extremely broad and covers many common email, support, content, and operational tasks, increasing the chance the agent will invoke this high-privilege skill for routine requests. Over-broad routing expands the attack surface because unrelated prompts may gain access to destructive or sensitive Sequenzy operations without a narrowly scoped trigger.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The skill explicitly advertises destructive campaign lifecycle actions, including campaigns cancel, that execute with no confirmation prompt, enabling the agent to stop scheduled or actively sending campaigns immediately. In a broadly activated skill, this materially raises the risk of autonomous high-impact business actions from ambiguous, mistaken, or adversarial requests.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
- segments `list`, `create`, `update`, `delete`, and `count`, including `--match any`, nested filter roots, custom event filters, and saved-segment composition filters
- templates `list`, `get`, `create`, `update`, and `delete`, with `list` supporting label filters and `create`/`update` accepting labels, raw HTML, or Sequenzy block JSON
- campaigns `list`, `get`, `create`, `update` including label and reply-to updates, `schedule`, and `test`, with `list` supporting label filters, `create` accepting labels plus raw HTML, Sequenzy block JSON, or prompt-generated content, `update` accepting labels plus raw HTML or Sequenzy block JSON, and `schedule` returning a review preview link; `create` and `schedule` both accept the audience via `--segment` or `--target-lists-json`/`--target-lists-file`
- campaign lifecycle control with `campaigns cancel` (stops scheduled, paused, waiting-approval, or sending campaigns immediately, no confirmation prompt), `campaigns unschedule` (returns a scheduled campaign or recurring series to draft), `campaigns pause` and `campaigns resume` for an active send (resume supports `--spread-over-hours`), `campaigns delete` (blocked while sending, scheduled, or paused - cancel first), and `campaigns duplicate` with `--mode campaign|ab_test|variant`
- campaign audience inspection with `campaigns audience`, true-to-send HTML previews with `campaigns render` / `templates render` / `sequences render` (subscriber or ad-hoc personalization, locale, tracking, `--out`), recurring sends with `campaigns schedule --repeat weekly|monthly`, and post-send re-engagement with `campaigns resend-to-non-openers`
- ab-tests `list`, `get`, `stats`, `restart`, `update-variant`, `create`, `add-variant`, `delete-variant`, and `delete`; create/add-variant/delete-variant/delete work on campaign A/B tests in draft status, variant A is the protected control, and `restart` reruns a finished sequence A/B test
- MCP template and campaign tools support labels on list/create/updat
...[truncated 25 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The command reference explicitly notes that campaigns cancel performs a state-changing action with no confirmation prompt. In an agent-operated context, this increases the risk of unintended autonomous disruption of live or scheduled campaigns from ambiguous prompts, mistaken IDs, or tool misuse.

Content

Scanner excerpt · references/command-reference.md (reported line 668)May include surrounding context.

md
- `campaigns get` now includes saved reply-to details when the campaign has a reply profile
- only draft campaigns can be updated through this API path
- there is no CLI command for immediate send; schedule with a near-future `--at` timestamp instead
- `cancel` works from scheduled, sending, paused, waiting_approval, and rejected statuses; it shows no confirmation prompt so a bad send can be stopped fast
- `pause` only works on a campaign in sending status; `resume` only works on a paused campaign
- `resume --spread-over-hours` accepts integers from 1 to 72 to spread the remaining delivery
- `delete` is blocked while the campaign is sending, scheduled, or paused; cancel it first

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file describes sequenzy landing-pages delete lp_123 without any adjacent warning, confirmation note, or explanation of impact. Unlike other destructive commands in the same document that explicitly mention prompts or irreversible effects, this entry omits a user-facing warning about deleting content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The Sequences section includes sequenzy sequences delete seq_123 and notes the API mapping, but it does not warn the user about deletion impact, reversibility, or confirmation behavior. For a command that removes workflow assets, the markdown should disclose the destructive nature clearly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.