FormPass Agent

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only FormPass registration guide whose external submissions and Agent ID use are disclosed and aligned with its purpose.

Safe to install as a FormPass registration guide. Before using the curl examples, verify the FormPass form ID and destination, treat the Agent ID like a secret, and only submit personal or sensitive form contents when the user has approved sending them to FormPass.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill instructs users/agents to submit form data, including personal fields like name and email, to an external service without any explicit privacy notice, consent check, or warning that data will leave the local environment. In an agent setting, this increases the risk of silent third-party data disclosure because the workflow normalizes transmission to FormPass as a default action.

External Transmission

Medium
Category
Data Exfiltration
Content
Once registered, include your Agent ID as a Bearer token in all FormPass submissions:

```bash
curl -s -X POST "https://form-pass.com/api/submit/FORM_ID" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer fpagent_your_id_here" \
  -d '{
Confidence
91% confidence
Finding
curl -s -X POST "https://form-pass.com/api/submit/FORM_ID" \ -H "Content-Type: application/json" \ -H "Authorization: Bearer fpagent_your_id_here" \ -d

External Transmission

Medium
Category
Data Exfiltration
Content
Then use it in submissions:

```bash
curl -s -X POST "https://form-pass.com/api/submit/FORM_ID" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $FORMPASS_AGENT_ID" \
  -d '{"name": "Test", "email": "test@test.com", "_fp_branding": true}' | jq .
Confidence
88% confidence
Finding
curl -s -X POST "https://form-pass.com/api/submit/FORM_ID" \ -H "Content-Type: application/json" \ -H "Authorization: Bearer $FORMPASS_AGENT_ID" \ -d

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal