Formidable Forms

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate Formidable Forms integration, but it needs review because it can delete or modify production form data and send authenticated proxy requests without explicit safety guidance.

Install only if you trust Membrane and the connected WordPress/Formidable Forms account with the relevant form data. Use least-privilege credentials, confirm exact form/field/entry IDs before any delete or bulk update, back up important forms and entries first, and avoid proxy requests unless a scoped built-in action cannot do the job.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
79% confidence
Finding
The skill advertises destructive actions such as deleting entries, fields, and forms without warning that these operations may be irreversible or require confirmation. In an agent setting, this increases the chance of accidental data loss if the model selects and executes a destructive action from a loosely phrased user request.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The proxy request feature enables arbitrary API requests to an external service and states that authentication headers are injected automatically, but it does not warn that user data may be transmitted off-platform. In a tool-using agent context, this can lead to unintended exfiltration of sensitive form contents or administrative data if the agent uses proxy requests too freely.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal