Back to skill

Security audit

plaud-recordings-to-google-calendar-events

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it reads Plaud meeting transcripts, creates matching Google Calendar events, and logs the results to Google Sheets.

Before installing, confirm you are comfortable letting the connected workflow read Plaud transcripts and store selected transcript quotes, recording links, event details, and ledger entries in Google Calendar and Google Sheets. For sensitive meetings, review the generated events and descriptions before relying on scheduled automation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill processes potentially sensitive meeting transcripts and then writes derived data and transcript excerpts into external services such as Google Calendar and Google Sheets, but it does not present a clear up-front user warning or explicit consent checkpoint before doing so. This can expose private conversation details, scheduling information, and third-party data to systems the user may not expect, increasing privacy and compliance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.