Back to skill

Security audit

Tmp.SnUxDV6npc

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed meeting-management helper that uses Tencent Meeting and Feishu in ways that match its stated purpose, with user confirmation rules for sensitive actions.

Install only if you intend to connect this agent to Tencent Meeting and a Feishu Bitable. Review the global tmeet install, Feishu app permissions, and ~/.config credential files, and require explicit confirmation before creating, canceling, inviting, removing, kicking, calling, or writing task-board records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill invokes shell commands, writes local config files, and uses networked APIs (tmeet and Feishu), but it does not declare corresponding permissions. This creates a transparency and consent problem: an agent could perform external actions or persist secrets/configuration without the permission model clearly surfacing that risk to users or the host platform.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Several triggers are broad regexes and generic phrases such as '创建会议', '查看会议列表', and '我要开.*会', which can match ordinary conversational requests. Because this skill can drive shell/network actions and external systems, overbroad activation raises the risk of unintended execution, privacy exposure, or accidental state changes in the wrong context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.