Formstack

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Florm integration that can read and manage form data through Membrane, including deleting individual form responses when directed.

Install only if you intend to let the agent operate on your Florm workspace through Membrane. Before deletes or raw proxy requests, confirm the exact form or response ID, review the expected impact, and prefer list/get actions before mutation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly documents destructive capabilities such as deleting forms and submissions, but provides no guidance to require user confirmation, scope validation, or safeguards before executing them. In an agentic setting, this increases the risk of accidental or overly broad destructive actions, especially if a user request is ambiguous or the agent misinterprets intent.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal