Environment variable access combined with network send.
- Code
- suspicious.env_credential_access
- Location
- index.js:11
- Evidence
const BASE_URL = (process.env.SUPERAGNT_API_URL || 'https://api.superagnt.com') + '/v1/connections/heyreach'
Security audit
Security checks for vulnerabilities and agentic risk
This is a real HeyReach/Superagnt outreach plugin, but it exposes high-impact organization administration and API-key actions that are broader than the advertised outreach use case.
Review this plugin carefully before installing. It appears to be a legitimate Superagnt-to-HeyReach integration, but it can do more than routine campaign analytics: it can send LinkedIn conversation messages, change campaigns and lists, delete leads or webhooks, create webhooks, invite organization users including admins, and create workspace API keys. Install it only for agents and users you trust to operate your HeyReach workspace, and require explicit confirmation for outbound, destructive, or account-administration actions.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.env_credential_access
const BASE_URL = (process.env.SUPERAGNT_API_URL || 'https://api.superagnt.com') + '/v1/connections/heyreach'