Activecampaign Automation

Security checks across malware telemetry and agentic risk

Overview

This skill transparently helps an agent make real ActiveCampaign CRM and marketing changes through Rube MCP, so it is appropriate if you intend that access.

Install only if you want an agent to operate on your ActiveCampaign account through Rube/Composio. Confirm exact contacts, list IDs, tags, and automation IDs before mutating actions, be careful with subscriptions and marketing consent, and use a limited or test account where practical.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
This skill enables state-changing CRM and marketing actions such as creating contacts, changing tags, subscribing or unsubscribing lists, enrolling users in automations, and creating tasks, but it does not include clear user-facing warnings, confirmation requirements, or guardrails for potentially sensitive modifications. In an agent setting, that increases the risk of unintended or over-broad changes to customer records and marketing consent state, which can cause compliance, operational, and reputational harm.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal