Back to skill

Security audit

Plaud

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Plaud connector for reading a user's own recordings, notes, and transcripts through AgentPMT, with sensitive-data handling worth user attention but no evidence of hidden or malicious behavior.

Install only if you want your agent to access Plaud recordings through AgentPMT. Treat transcripts and notes as potentially confidential, use the narrowest file or date filters practical, and confirm before sending excerpts or summaries to external tools such as CRMs, shared documents, task managers, or email.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill explicitly enables access to highly sensitive recordings, transcripts, and AI-generated notes, but it does not require a privacy warning, user confirmation, or minimization guidance before processing or redistributing that content into other tools. Because meeting recordings often contain personal, confidential, legal, HR, or commercial data, omission of explicit privacy handling increases the risk of inadvertent exposure or oversharing.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The schema exposes actions to list recordings and retrieve transcripts, notes, and user data from a connected Plaud account, but it does not communicate that these artifacts may contain highly sensitive personal, employment, health, legal, or confidential business information. In an agent ecosystem, missing privacy and sensitivity guidance increases the chance that downstream agents over-collect, summarize, or disclose recording contents without appropriate user awareness, consent checks, or least-privilege handling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.