Back to skill

Security audit

Google Meet

Security checks for vulnerabilities and agentic risk

Overview

This Google Meet connector is mostly coherent, but it routes sensitive meeting data through a third-party service and lets mutable remote instructions outrank the reviewed local skill text.

Review this skill before installing in an organization. Only connect accounts whose Meet history the agent is authorized to access, avoid broad transcript or recording retrieval unless needed, require explicit confirmation before ending a conference, and prefer pinned or OpenClaw setup paths over unpinned npx commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:386
Finding

Mutable Remote Instructions Can Override the Audited Skill Definition

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:386-391
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Code Snippet:

markdown
## Live Schema And Examples
Use the compact schema above for ordinary calls. Before a new production integration, or whenever parameters, enum values, nested objects, outputs, or examples are unclear, fetch live details first.

- Exact schema: call `agentpmt-tool-search-and-execution` with `action: "get_schema"`, and `tool_id: "google-meet-connector"`.
- Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "google-meet-connector"`, or call this product with `action: "get_instructions"` when the product tool is already selected.
- Treat returned live schema and instructions as more specific than this generated summary.

Technical Analysis

The Skill directs the agent to retrieve mutable instructions from an external AgentPMT service and treat those instructions as more authoritative than the locally installed and audited Skill definition. Although retrieving a live schema can be legitimate, granting precedence to remotely supplied natural-language instructions creates an instruction-control channel outside the reviewed package.

The response to get_instructions is not constrained in the local documentation to a strict data-only format, cryptographically pinned version, or allowlisted set of fields. If the AgentPMT service, connector configuration, or response path is compromised, instruction-like content could alter tool-selection behavior, encourage collection of unrelated information, or attempt to weaken session safety constraints.

Attack Path

  1. An attacker compromises the AgentPMT service, the Google Meet connector configuration, or another component capable of modifying the get_instructions response.
  2. The agent follows the Skill and calls get_instructions.
  3. The ...[truncated 904 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the instruction that remote content is more authoritative than the audited local Skill.
  • Treat all remotely returned instructions and examples as untrusted data rather than executable agent directives.
  • Prefer a versioned, machine-readable schema pinned to a specific connector release.
  • Validate remote schema responses against a restrictive local allowlist covering action names, parameter names, types, and permitted endpoints.
  • Reject unexpected natural-language instructions, tool-routing directives, credential requests, and attempts to modify safety constraints.
  • Use cryptographic signatures or integrity hashes for remotely maintained schemas where feasible.
  • Require explicit user confirmation before acting on a remote response that materially expands data access or changes an operation's effect.

other

Warning
Location
SKILL.md:292
Finding

Sensitive Google Meet Data Is Routed Through a Third-Party Connector

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:292-307, SKILL.md:317-323, and SKILL.md:522-523
Vulnerability Type: other: Third-Party Sensitive Data Exposure
Risk Level: Medium

Vulnerable Code Snippet:

markdown
##### list_transcript_entries

List individual spoken entries within a transcript, including speaker, text, language, and timestamps.

**Required parameters:**
- `transcript_name` (string) -- transcript resource name

**Optional parameters:**
- `page_size` (integer, 1-250, default 25) -- max results per page
- `page_token` (string) -- pagination token

**Example:**
```json
{"action":"list_transcript_entries","transcript_name":"conferenceRecords/abc/transcripts/xyz","page_size":100}
text

```markdown
1. `list_conference_records` with a space filter to find the conference
2. `list_participants` to see who attended and their join/leave times
3. `list_transcripts` to find available transcripts
4. `list_transcript_entries` to read the full conversation
5. `list_recordings` to find the video recording
6. Use the Google Drive tool with `drive_file_id` to download the recording MP4
markdown
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Technical Analysis

The Skill accesses participant identities, attendance history, recording identifiers, transcript identifiers, and full speaker-attributed meeting text through an AgentPMT-hosted connector rather than through a direct Google API integration. This behavior is related to the declared connector functionality and is disclosed in the Skill, so the audit found no evidence of covert exfiltration.

Nevertheless, AgentPMT becomes an additional trusted processor for highly sensitive organizational and personal information. The reviewed files do not specify retention limits, server-side encryption controls, deletion guarante ...[truncated 1708 chars]

Remediation
View remediation

Remediation Suggestions

  • Prefer direct Google Meet API integration when feasible, eliminating the additional data-processing intermediary.
  • Clearly disclose that AgentPMT processes meeting metadata and transcript content before account authorization.
  • Obtain explicit user confirmation before retrieving full transcripts, participant lists, or recording references.
  • Request only the records and fields required for the stated task; default to narrow filters and smaller page sizes.
  • Avoid retrieving full transcript entries when a metadata-only request or user-selected excerpt is sufficient.
  • Document transport encryption, server-side encryption, retention periods, deletion procedures, subprocessors, regional processing, tenant isolation, and incident-response controls.
  • Provide administrative access controls and audit logs for transcript and recording operations.
  • Redact or minimize sensitive transcript content before passing it to additional tools or models.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:463
Finding

Unpinned Dependencies Are Downloaded and Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:463-467
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code Snippet:

markdown
skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

### Technical Analysis

The documented setup commands use `npx`, which can retrieve and execute package code, without pinning the `skills` CLI to an exact version. The referenced AgentPMT Skill repository is also not pinned to an immutable commit or verified artifact digest.

Consequently, the effective setup payload can change after this Skill has been reviewed. The required setup Skills are not included in the audited project, which contains only `SKILL.md` and `schema.md`, so their behavior could not be evaluated as part of this audit.

This is a supply-chain weakness rather than evidence that the currently referenced packages are malicious. Exploitation requires compromise or malicious modification of a package, account, repository, distribution channel, or future release.

### Attack Path

1. An attacker compromises the package used by `npx`, its publisher account, the AgentPMT repository, or another relevant distribution source.
2. The attacker publishes a modified version containing malicious installation or runtime behavior.
3. A user follows the documented command without an explicit version or immutable commit.
4. `npx` downloads and executes the changed package with the invoking user's privileges.
5. The malicious dependency accesses resources available to that user, such as local files, environment variables, credentials, or network services.

### Impact Assessment

Successful exploitation could execute arbitrary code under the privileges of the user running the installation command. Depending on that environment, this could expose local files
...[truncated 323 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the skills CLI to an exact, reviewed version in every npx command.
  • Pin the AgentPMT Skill source to an immutable commit rather than a mutable branch or latest release.
  • Verify cryptographic checksums or signatures before installation.
  • Use lockfiles and reproducible installation procedures where supported.
  • Vendor required setup Skills into the reviewed package when licensing and maintenance constraints permit.
  • Audit the account setup Skill before allowing it to handle credentials or modify connector configuration.
  • Run installation in a restricted environment with minimum filesystem, environment-variable, and network access.
  • Avoid automatically executing newly downloaded packages in privileged or credential-rich sessions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill exposes high-sensitivity meeting artifacts including participant identities, join/leave times, recordings, and full transcripts, but does not prominently warn about privacy, consent, retention, or least-privilege use. In a meeting tool context this materially increases the risk of inadvertent surveillance, over-collection, or disclosure of regulated or confidential communications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

end_conference is a destructive action that can abruptly terminate an active meeting, causing immediate loss of availability and disrupting live communications. Because the documentation lacks a strong warning or confirmation requirement, an agent or operator may invoke it accidentally during routine space-management tasks.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 334)May include surrounding context.

md
#### Notes

- Conference records are automatically deleted 30 days after the conference ends
- Recording and transcript files persist in Google Drive beyond the 30-day conference record window
- `list_conference_records` only returns conferences where the authenticated user is the organizer
- To download recordings, use the Google Drive tool with the `drive_file_id` from the recording response

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 522)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/google-meet-connector
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 523)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/google-meet-connector
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents an end_conference action that terminates an active conference, which can affect meeting continuity and is potentially irreversible for participants. The description states what the action does but provides no caution, confirmation note, or user-facing warning about ending a live meeting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The get_recording action retrieves recording details, which can relate to sensitive meeting artifacts. The markdown lacks any warning that recordings may contain private or confidential information and should be handled carefully.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file documents get_transcript, list_transcript_entries, and list_transcripts, which expose transcript content and spoken entries that may contain sensitive personal or organizational information. The markdown provides functional descriptions only and does not warn users about privacy implications or the need for appropriate authorization before accessing transcript data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.