rewardful
Warn
Audited by Snyk on May 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill's SKILL.md requires connecting to Rewardful via the Membrane CLI (membrane connect --connectorKey rewardful) and running actions (membrane action run ...; "The result is in the
outputfield of the response"), which causes the agent to ingest and act on untrusted, user-generated third-party data (affiliates/customers/referrals) returned from the external service.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). Rewardful is a specialist SaaS for managing referral/affiliate programs and explicitly mentions "Commissions" and "automate payouts" (i.e., handling affiliate payments). The skill is not a generic browser or HTTP tool — it is a connector to a financial-adjacent service and uses Membrane actions to interact with Rewardful data (including affiliates/commissions). Those actions can be expected to include operations that create/modify commissions or trigger payouts, which are direct financial-execution behaviors. Therefore this skill grants explicit financial execution capability.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata