Digiforma

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Digiforma API helper, but it can retrieve trainee contact details and invoice data when given a valid API key.

Install only if you trust the publisher and have a legitimate need to query Digiforma. Use a least-privileged or read-only API key where possible, and avoid retrieving or sharing trainee emails, phone numbers, trainer contact details, or invoice amounts unless the requester is authorized to see them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill includes ready-made queries that retrieve personally identifiable information such as names, email addresses, and phone numbers for trainees and trainers, but provides no privacy constraints, authorization checks, or output-minimization guidance. In an agent setting, this increases the chance of over-collection or disclosure of sensitive training-management data to users who may not be entitled to receive it.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal