Google Forms

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Google Forms integration that discloses its Membrane-based authentication and API access, though write/delete operations should be reviewed carefully.

Install this only if you want an agent to work with your Google Forms through Membrane. Prefer listed Membrane actions over raw proxy requests, review any POST/PUT/PATCH/DELETE operation before it runs, and use the least-privileged Google account or connection that fits the task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The invocation description is broad enough to trigger on many routine Google Forms-related requests, which can cause the agent to select this skill in situations where user intent is underspecified. Because the skill supports authenticated actions and direct API requests, over-invocation increases the chance of unnecessary access to external systems or unintended modifications.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation explicitly permits direct proxy requests with mutating methods like POST, PUT, PATCH, and DELETE, but does not instruct the agent to confirm intent before making state-changing calls. In a skill that interfaces with live Google Forms resources, this omission can lead to accidental edits, deletions, or workflow-triggering changes when the agent uses the proxy path instead of safer predefined actions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal