Formaloo

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent Formaloo integration, but it gives an agent broad authenticated ability to change or delete Formaloo data without clear confirmation guardrails.

Install only if you trust Membrane and intend to let an agent operate on your Formaloo account. Before any create, update, delete, workflow, or bulk operation, require the agent to show the exact action or endpoint, payload, target workspace or form, and expected effect; revoke the connection when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal