Back to skill

Security audit

plaud

Security checks across malware telemetry and agentic risk

Overview

This skill clearly describes Plaud account access for retrieving recordings, transcripts, notes, and file metadata, with no hidden code or destructive behavior found.

Install only if you want your assistant to access Plaud recordings, AI notes, and full transcripts through your connected account. Treat transcript content as potentially confidential, and confirm before sending summaries, quotes, or action items into CRM, email, shared documents, or other third-party tools.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill enables access to highly sensitive voice recordings, transcripts, and AI notes, but it does not present a clear user-facing privacy warning or require explicit confirmation before processing or sharing this content. Because transcripts may contain confidential business, personal, or regulated information, omission of an explicit privacy notice increases the risk of unintentional disclosure through downstream automations and external tools.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The schema exposes operations for retrieving highly sensitive data including authenticated user identity, full transcripts with speaker attribution, AI-generated notes, and recording metadata, but it provides no privacy warning, consent guidance, or data-handling constraints. In a voice-recording skill, this omission increases the likelihood that an agent or downstream integrator will access or summarize sensitive meeting, interview, or memo content without adequate user awareness or confirmation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.