Fundraise Up

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Fundraise Up API guide, but it gives an agent access to donor data and live donation/payment actions without enough formal scoping or approval guardrails.

Review before installing. Use test-mode or least-privilege Fundraise Up API keys, avoid granting create-donation or donor-portal-link permissions unless needed, require human confirmation for every live write action, and redact donor PII from prompts, logs, and summaries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The donation-creation examples transmit sensitive donor PII, including name, email, phone, and mailing address, and the documentation does not prominently warn users to minimize, redact, or obtain consent before sending such data. In a fundraising context this increases the risk of privacy violations, accidental over-collection, and unsafe handling of regulated personal data when operators copy examples into production workflows.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal