rewardful

Warn

Audited by Snyk on May 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill's SKILL.md requires connecting to Rewardful via the Membrane CLI (membrane connect --connectorKey rewardful) and running actions (membrane action run ...; "The result is in the output field of the response"), which causes the agent to ingest and act on untrusted, user-generated third-party data (affiliates/customers/referrals) returned from the external service.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Rewardful is a specialist SaaS for managing referral/affiliate programs and explicitly mentions "Commissions" and "automate payouts" (i.e., handling affiliate payments). The skill is not a generic browser or HTTP tool — it is a connector to a financial-adjacent service and uses Membrane actions to interact with Rewardful data (including affiliates/commissions). Those actions can be expected to include operations that create/modify commissions or trigger payouts, which are direct financial-execution behaviors. Therefore this skill grants explicit financial execution capability.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 2, 2026, 11:49 PM
Issues
2
Security Audit — snyk — rewardful