Back to skill

Security audit

SMB Sales Boost

Security checks for vulnerabilities and agentic risk

Overview

This skill has powerful sales, billing, email, and integration features, but the artifacts disclose those effects and add confirmation gates for high-impact actions.

Install only if you intend to let an agent use your SMB Sales Boost account. Keep the API key in the environment, require clear approval before any money, email, deletion, or integration action, set maxCredits on searches and exports, and store exported lead files and webhook secrets carefully.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (40)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · REFERENCE.md (reported line 29)May include surrounding context.

md
| `POST /lead-export-history/re-export` | Rebuild a file from stored copies | free | export |
| `POST /lead-export-history/refresh-and-export` | Refresh, then rebuild a file | free | export |
| `GET /export-formats`, `GET /export-formats/{id}` | List or get export formats | | |
| `POST /export-formats`, `PATCH /export-formats/{id}`, `DELETE /export-formats/{id}` | Create, update, delete | | |
| `POST /export-formats/{id}/set-default` | Make a format the default | | |
| `GET /export-blacklist`, `POST /export-blacklist`, `DELETE /export-blacklist/{id}` | Domains to keep out of exports | | |
| `GET /filter-presets`, `POST /filter-presets`, `DELETE /filter-presets/{id}` | Saved searches for email schedules | | |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · REFERENCE.md (reported line 31)May include surrounding context.

md
| `GET /export-formats`, `GET /export-formats/{id}` | List or get export formats | | |
| `POST /export-formats`, `PATCH /export-formats/{id}`, `DELETE /export-formats/{id}` | Create, update, delete | | |
| `POST /export-formats/{id}/set-default` | Make a format the default | | |
| `GET /export-blacklist`, `POST /export-blacklist`, `DELETE /export-blacklist/{id}` | Domains to keep out of exports | | |
| `GET /filter-presets`, `POST /filter-presets`, `DELETE /filter-presets/{id}` | Saved searches for email schedules | | |
| `GET /keyword-lists`, `POST /keyword-lists`, `PUT /keyword-lists/{id}`, `DELETE /keyword-lists/{id}` | Keyword lists | | |
| `GET /email-schedules`, `POST /email-schedules`, `PATCH /email-schedules/{id}`, `DELETE /email-schedules/{id}` | Scheduled lead emails | credits, sends email (an active schedule, the default on create, sends its first email within about 15 minutes) | |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · REFERENCE.md (reported line 211)May include surrounding context.

md
| `GET /export-formats`, `GET /export-formats/{id}` | List or get export formats | | |
| `POST /export-formats`, `PATCH /export-formats/{id}`, `DELETE /export-formats/{id}` | Create, update, delete | | |
| `POST /export-formats/{id}/set-default` | Make a format the default | | |
| `GET /export-blacklist`, `POST /export-blacklist`, `DELETE /export-blacklist/{id}` | Domains to keep out of exports | | |
| `GET /filter-presets`, `POST /filter-presets`, `DELETE /filter-presets/{id}` | Saved searches for email schedules | | |
| `GET /keyword-lists`, `POST /keyword-lists`, `PUT /keyword-lists/{id}`, `DELETE /keyword-lists/{id}` | Keyword lists | | |
| `GET /email-schedules`, `POST /email-schedules`, `PATCH /email-schedules/{id}`, `DELETE /email-schedules/{id}` | Scheduled lead emails | credits, sends email (an active schedule, the default on create, sends its first email within about 15 minutes) | |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

The documented DELETE /filter-presets/{id} becomes dangerous in this skill context because section 9 states deleting a preset first deletes every email schedule that still uses it. A generic delete action against an identifier can therefore trigger broader destructive side effects than a user or agent may expect, including stopping scheduled lead delivery workflows and altering future outbound communications.

Content

Scanner excerpt · REFERENCE.md (reported line 32)May include surrounding context.

md
| `POST /export-formats`, `PATCH /export-formats/{id}`, `DELETE /export-formats/{id}` | Create, update, delete | | |
| `POST /export-formats/{id}/set-default` | Make a format the default | | |
| `GET /export-blacklist`, `POST /export-blacklist`, `DELETE /export-blacklist/{id}` | Domains to keep out of exports | | |
| `GET /filter-presets`, `POST /filter-presets`, `DELETE /filter-presets/{id}` | Saved searches for email schedules | | |
| `GET /keyword-lists`, `POST /keyword-lists`, `PUT /keyword-lists/{id}`, `DELETE /keyword-lists/{id}` | Keyword lists | | |
| `GET /email-schedules`, `POST /email-schedules`, `PATCH /email-schedules/{id}`, `DELETE /email-schedules/{id}` | Scheduled lead emails | credits, sends email (an active schedule, the default on create, sends its first email within about 15 minutes) | |
| `POST /email-schedules/{id}/trigger` | Send a schedule now | credits, sends email | export |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
83% confidence
Finding

DELETE /keyword-lists/{id} is risky because section 10 notes that deleting a list silently removes it from presets; if it was a negative list, schedules may begin sending and charging for more leads, and if it was the only positive filter, schedules may stop sending entirely. This hidden coupling makes a simple parameterized delete materially affect downstream lead selection, charges, and outbound data flows.

Content

Scanner excerpt · REFERENCE.md (reported line 33)May include surrounding context.

md
| `POST /export-formats/{id}/set-default` | Make a format the default | | |
| `GET /export-blacklist`, `POST /export-blacklist`, `DELETE /export-blacklist/{id}` | Domains to keep out of exports | | |
| `GET /filter-presets`, `POST /filter-presets`, `DELETE /filter-presets/{id}` | Saved searches for email schedules | | |
| `GET /keyword-lists`, `POST /keyword-lists`, `PUT /keyword-lists/{id}`, `DELETE /keyword-lists/{id}` | Keyword lists | | |
| `GET /email-schedules`, `POST /email-schedules`, `PATCH /email-schedules/{id}`, `DELETE /email-schedules/{id}` | Scheduled lead emails | credits, sends email (an active schedule, the default on create, sends its first email within about 15 minutes) | |
| `POST /email-schedules/{id}/trigger` | Send a schedule now | credits, sends email | export |
| `POST /ai/suggest-categories` | Suggest customer categories | | AI |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
81% confidence
Finding

DELETE /email-schedules/{id} is destructive beyond simple removal because section 11 says it also deletes the schedule's unsubscribed-recipient list. In this skill, where schedules can automatically email lead exports containing business contact details, accidental deletion can erase suppression state and create compliance/operational risk if the schedule is recreated later without that history.

Content

Scanner excerpt · REFERENCE.md (reported line 34)May include surrounding context.

md
| `GET /export-blacklist`, `POST /export-blacklist`, `DELETE /export-blacklist/{id}` | Domains to keep out of exports | | |
| `GET /filter-presets`, `POST /filter-presets`, `DELETE /filter-presets/{id}` | Saved searches for email schedules | | |
| `GET /keyword-lists`, `POST /keyword-lists`, `PUT /keyword-lists/{id}`, `DELETE /keyword-lists/{id}` | Keyword lists | | |
| `GET /email-schedules`, `POST /email-schedules`, `PATCH /email-schedules/{id}`, `DELETE /email-schedules/{id}` | Scheduled lead emails | credits, sends email (an active schedule, the default on create, sends its first email within about 15 minutes) | |
| `POST /email-schedules/{id}/trigger` | Send a schedule now | credits, sends email | export |
| `POST /ai/suggest-categories` | Suggest customer categories | | AI |
| `POST /ai/generate-keywords` | Delete all keyword lists and regenerate them | | AI |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · REFERENCE.md (reported line 55)May include surrounding context.

md
| `GET /integrations`, `GET /integrations/{id}` | List integrations, get one | | integrations |
| `POST /integrations/webhook` | Create a webhook integration (returns the signing secret once) | sends data out (from then on, automatically) | integrations |
| `PATCH /integrations/{id}` | Rename, pause, re-enable, change events, destination or header `apiKey`, Pipedrive deals | sends data out (when re-pointed, re-enabled or events added) | integrations |
| `DELETE /integrations/{id}` | Delete an integration | | integrations |
| `GET /integrations/{id}/deliveries` | Newest 50 delivery attempts | | integrations |
| `POST /integrations/{id}/deliveries/{deliveryId}/retry` | Re-send one delivery | sends data out | integrations |
| `POST /integrations/{id}/test` | Send a synthetic test event | sends data out | integrations |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

md
| `GET /integrations`, `GET /integrations/{id}` | List integrations, get one | | integrations |
| `POST /integrations/webhook` | Create a webhook integration (returns the signing secret once) | sends data out (from then on, automatically) | integrations |
| `PATCH /integrations/{id}` | Rename, pause, re-enable, change events, destination or header `apiKey`, Pipedrive deals | sends data out (when re-pointed, re-enabled or events added) | integrations |
| `DELETE /integrations/{id}` | Delete an integration | | integrations |
| `GET /integrations/{id}/deliveries` | Newest 50 delivery attempts | | integrations |
| `POST /integrations/{id}/deliveries/{deliveryId}/retry` | Re-send one delivery | sends data out | integrations |
| `POST /integrations/{id}/test` | Send a synthetic test event | sends data out | integrations |

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · REFERENCE.md (reported line 231)May include surrounding context.

md
| `q` | Plain substring search | text |
| `urf` | Buying signal types | comma-separated |

A hash has no key for `positiveKeywords`: `ni`, `ui`, `cli` and `di` each match only their own column and none of them searches AI Categories, while keywords from a positive keyword list in `nkl` are searched like `positiveKeywords` (including AI Categories). So to reproduce a `positiveKeywords` search, create a positive keyword list and put its id in `nkl`. A positive filter is required: a non-empty `ni`, `ui`, `cli` or `di`, or the id of one of your own positive keyword lists (with at least one keyword) in `nkl`/`ukl`/`ckl`/`dkl`. A negative list alone does not count, ids that are not yours are dropped, and a preset without a positive filter silently sends nothing. Example in Python: `"#" + urllib.parse.urlencode({"ni": json.dumps(["*dental*", "*dentist*"]), "si": "TX,OK"})`. Other dashboard filters are not applied by schedules. Presets cannot be edited: create a new one, point the schedule at it with `PATCH` (add `"isActive": false` to the same call if the user should review the new search before it sends), then delete the old one (deleting a preset first deletes every schedule that still uses it: check `GET /email-schedules` for its `filterPresetId` and name those schedules to the user before deleting).

## 10. Keyword lists

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The integration management section exposes a cluster of high-risk parameterized actions—delete, re-point, retry, test, and recreate integrations—that can send lead/contact data to external destinations or permanently destroy configuration. In this skill context, those actions govern third-party exfiltration paths and include one-time secrets; misuse of an id or target URL can redirect sensitive lead data outside SMB Sales Boost or irreversibly lose a webhook signing secret.

Content

Scanner excerpt · REFERENCE.md (reported line 348)May include surrounding context.

md
| 3 | `GET /integrations/{id}` | | `Integration` | Read only |
| 4 | `POST /integrations/webhook` | `provider` (`zapier`, `n8n`, `make`, `pipedream`, `clay`, `generic_webhook`), `targetUrl`, `events` (1 or more event names), optional `displayName` (1-100 characters), optional `apiKey` (up to 500 characters, sent to the destination as `X-SMB-API-Key`; pass the body with `--body-file`) | `{"integration": Integration, "signingSecret"}` | Sends data out from now on; emails the owner; `--confirm`. `signingSecret` is shown only this once: give it to the user, never log or store it (the script does not save this response with `--out`). Not safe to repeat after a timeout: check `GET /integrations` first. The same provider and `targetUrl` again returns `409 integration_exists`; a changed URL (even a trailing slash) creates a second integration with its own secret. If the integration exists but you did not get its `signingSecret`, read it (`GET /integrations/{id}`), show the user its provider, destination URLs and events, and with their yes delete it (row 6) and create it again with the same values (both need `--confirm`; events that went to different URLs are restored with a `PATCH` of `subscriptions`). |
| 5 | `PATCH /integrations/{id}` | Any of `displayName`, `status` (`connected` or `disabled`; `needs_attention` is set only by the system and sending it is a `400 validation_error`, except as a no-op on an integration that already has it), `subscriptions` (replaces the whole list: `[{"eventType", "targetUrl"?, "isActive"?, "config"?}]`, up to 20; a subscription without `targetUrl` takes `defaultTargetUrl`, else that event's current URL, else the integration's first URL for a new event), `defaultTargetUrl` (webhook integrations only, `400 bad_request` on a CRM; sent without `subscriptions` it re-points every existing subscription, inactive ones too, to this URL; to change only some events, send `subscriptions`), `apiKey` (string up to 500 characters, or `null` or `""` to sto
...[truncated 26 chars]

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

DELETE /integrations/{id}/field-mapping resets CRM field mappings to defaults, which can silently change what lead/contact fields are propagated to third-party CRMs on future deliveries. In a skill that handles exported business contact details and automatic integrations, resetting mappings can cause unintended disclosure, bad data placement, or compliance issues if users expect a constrained/custom mapping.

Content

Scanner excerpt · REFERENCE.md (reported line 356)May include surrounding context.

md
| 11 | `POST /integrations/{provider}/connect` | `provider` is `hubspot`, `salesforce` or `pipedrive`; optional `{"environment": "sandbox"}` (Salesforce only; the default is `production`) | `{"provider", "authorizationUrl", "expiresAt"}` | The user must open `authorizationUrl` in a browser within 10 minutes and approve; the CRM account they sign in to is the one connected, and the new integration then appears in `GET /integrations` with these events: HubSpot `lead.created` on and `lead.updated` present but off (turn it on with `PATCH`; `GET /integrations` shows each event's real `isActive`, while `defaultEvents` in `GET /integrations/providers` lists both); Salesforce `lead.created`; Pipedrive `lead.created` and `lead.updated`. Emails the owner. If the API key that asked for the link is revoked before the user approves, the connection fails with `key_revoked` and nothing is created. `--confirm`. Safe to repeat (a new link). `400 bad_request` only for a wrong `environment` (sent for a provider other than Salesforce, or not `production`/`sandbox`); `409 integration_limit` at 25 integrations; another provider name is `404`; `503 provider_unavailable` when the provider is not set up. |
| 12 | `GET /integrations/{id}/field-mapping` | optional `refresh=true` (re-read the CRM's field list; it is cached for 10 minutes) | HubSpot `{"smbFields", "contactFields", "companyFields", "cachedAt", "mapping"}`; Salesforce `{"smbFields", "leadFields", "contactFields", "accountFields", "cachedAt", "mapping"}`; Pipedrive `{"smbFields", "personFields", "organizationFields", "cachedAt", "mapping"}` | Reads the CRM |
| 13 | `PATCH /integrations/{id}/field-mapping` | HubSpot `{"contact"?, "company"?}`, Salesforce `{"lead"?}`, Pipedrive `{"person"?, "organization"?}`; each an object from an SMB Sales Boost field id (from `smbFields`) to a CRM field key (1-100 characters). Unknown field ids are dropped. The mapping is replaced as a whole: a scope you leave out is cleared. A scope of another p
...[truncated 26 chars]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
o rule, parameter or example is missed. Full parameter and field tables are in `REFERENCE.md` in this folder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
o rule, parameter or example is missed. Full parameter and field tables are in `REFERENCE.md` in this folder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
o rule, parameter or example is missed. Full parameter and field tables are in `REFERENCE.md` in this folder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
o rule, parameter or example is missed. Full parameter and field tables are in `REFERENCE.md` in this folder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
o rule, parameter or example is missed. Full parameter and field tables are in `REFERENCE.md` in this folder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

md
o rule, parameter or example is missed. Full parameter and field tables are in `REFERENCE.md` in this folder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
o rule, parameter or example is missed. Full parameter and field tables are in `REFERENCE.md` in this folder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

md
o rule, parameter or example is missed. Full parameter and field tables are in `REFERENCE.md` in this folder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

md
o rule, parameter or example is missed. Full parameter and field tables are in `REFERENCE.md` in this folder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

md
o rule, parameter or example is missed. Full parameter and field tables are in `REFERENCE.md` in this folder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

md
o rule, parameter or example is missed. Full parameter and field tables are in `REFERENCE.md` in this folder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
*Reference files:** `REFERENCE.md` (every parameter, field, status and error), `openapi.json` (the published OpenAPI 3.1 spec; where it differs from this skill,

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

md
## AI helpers

- `POST /ai/suggest-categories` with `companyName`, `companyDescription` and `productService` (optional `companyWebsite`, `excludeCategories`) returns 4-12 suggested customer categories for the user's business. Nothing is saved. Turn the suggestions into keywords yourself (for example "Dentists" becomes `["*dental*","*dentist*"]`).
- `POST /ai/generate-keywords` **deletes every existing keyword list** and regenerates lists from the account's target categories, which can only be set in the dashboard. If `GET /me` shows an empty `targetCategories`, it deletes the lists and generates nothing. Filter presets that point at keyword lists by id (`nkl`, `ukl`, `ckl` or `dkl` in the hash, which dashboard-saved presets also use) silently lose those keywords and exclusions when the lists are deleted, and the same applies to `DELETE /keyword-lists/{id}`: their email schedules can stop sending, or start emailing a broader set of leads and spending credits on them. Check `GET /filter-presets` first and pause any affected schedules. Only use it when the user explicitly wants all lists replaced (needs `--confirm`). Check progress with `GET /ai/keyword-status`.
- `POST /ai/auto-refine/enable` / `disable` with `{"listId": 42}` turn on or off the AI refinement of a keyword list and its paired list; `GET /ai/auto-refine/status?listId=42` shows progress. Enabling resets the list's score history, and the refinement rewrites the list's keywords, which changes what any email schedule using the list sends (pause those schedules first if the user wants to review). A `200` does not guarantee the run started: if `autoRefineEnabled` is true but `refinementStatus` stays `null`, call enable again a few minutes later.

## Integrations: sending leads to a CRM or automation tool

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The create-webhook description tells clients to delete and recreate an integration if the signingSecret was missed, effectively steering an agent toward a destructive follow-on action based on timeout/response ambiguity. In an autonomous tool-using assistant, this can trigger deletion and reconfiguration of live integrations, changing where PII is sent and disrupting service without sufficiently strong user re-approval.

Content

Scanner excerpt · openapi.json (reported line 260)May include surrounding context.

json
],
        "operationId": "createWebhookIntegration",
        "summary": "Create a webhook integration",
        "description": "Creates a webhook destination for one of the webhook providers (zapier, n8n, make, pipedream, clay, generic_webhook). From then on SMB Sales Boost sends lead data (business contact details) to targetUrl on every subscribed event, automatically, until the integration is disabled or deleted. Confirm the destination with the account owner first. The response includes signingSecret, used to verify the X-SMB-Signature header on every delivery; it is shown only once, so hand it to the user and do not log it. If the request times out, the integration may have been created: check GET /integrations first. Repeating the same provider and targetUrl returns 409 integration_exists; a different provider or a changed URL (even a trailing slash) creates a second integration with its own secret. The signing secret cannot be shown again, so if the integration exists but you did not get its signingSecret, delete it (DELETE /integrations/{id}) and create it again. The integration and its subscriptions are written together (all or nothing), and once it is written the response always carries the signingSecret; a 503 service_unavailable means nothing was created. Limits: targetUrl must be a public https URL; at most 25 integrations per account. Safeguard: when an API key (REST or MCP) creates a webhook, connects a CRM, changes where an integration sends data, adds or re-activates an event, or re-enables an integration, SMB Sales Boost records the key on the integration (createdVia / lastChangedVia, shown in the dashboard as 'Created via API key smbk_...') and emails the account owner. The account owner is emailed for each change. During bursts of more than 10 changes in an hour, further changes are combined into summary emails.",
        "requestBody": {
          "required": true,
          "content": {

Static analysis

No suspicious patterns detected.