Back to skill

Security audit

narrated-walkthrough-to-a-numbered-sop-document

Security checks across malware telemetry and agentic risk

Overview

This skill clearly describes a workflow that turns selected Plaud recordings into Google Docs SOPs and logs results in Google Sheets, with no hidden local execution or unrelated behavior found.

Install only if you are comfortable having Plaud transcript content and extracted procedure details sent to and stored in the connected Google Docs and Google Sheets accounts. Avoid using it for confidential, regulated, or highly sensitive recordings unless those services are approved for that data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow processes Plaud recordings and transcripts, then sends derived content to external services including Google Docs and Google Sheets, but the skill description does not clearly warn users about this data flow or the persistence of potentially sensitive operational information. This can lead users to unintentionally expose confidential procedures, safety notes, equipment details, or personal data contained in transcripts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.