Back to skill

Security audit

plaud-transcripts-corrected-with-your-own-terminology-glossary

Security checks across malware telemetry and agentic risk

Overview

This skill transparently automates a Plaud-to-Google Docs/Sheets transcript correction workflow, with sensitive data sharing that is expected for its purpose.

Install only if you are comfortable with Plaud recording content, glossary terms, summaries, action items, unknown-term flags, and run metadata being read from or written to your connected Google Sheets and Google Docs. For confidential, regulated, legal, medical, or client recordings, confirm that the selected Google workspace and sharing settings are approved before running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The workflow explicitly sends corrected transcripts, summaries, action items, and logged metadata to Google Docs and Google Sheets, which are third-party services that may receive sensitive meeting, client, medical, legal, or proprietary content. Because the skill does not clearly warn the user about this data flow, obtain explicit consent, or describe data-classification boundaries, it creates a real privacy and compliance risk rather than a purely informational issue.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.