Back to skill

Security audit

narrated-walkthrough-to-a-numbered-sop-document

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly describes a workflow that turns selected Plaud recordings into Google Docs SOPs and logs results in Google Sheets, with no hidden local execution or unrelated behavior found.

Install only if you are comfortable having Plaud transcript content and extracted procedure details sent to and stored in the connected Google Docs and Google Sheets accounts. Avoid using it for confidential, regulated, or highly sensitive recordings unless those services are approved for that data.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow processes Plaud recordings and transcripts, then sends derived content to external services including Google Docs and Google Sheets, but the skill description does not clearly warn users about this data flow or the persistence of potentially sensitive operational information. This can lead users to unintentionally expose confidential procedures, safety notes, equipment details, or personal data contained in transcripts.

Static analysis

No suspicious patterns detected.