Back to skill

Security audit

Meeting Autopilot

Security checks across malware telemetry and agentic risk

Overview

This meeting assistant is not malicious, but it would process calendars, emails, documents, attendee histories, notes, and meeting memory automatically with limited scoping controls.

Review carefully before installing. Use it only if you are comfortable with automatic processing of selected meetings and related communications, and avoid confidential HR, legal, medical, financial, client, or executive meetings unless your agent environment provides controls for opt-in calendars, data-source limits, private meetings, memory review, and deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill enables automatic activation 30 minutes before any calendar event, which is broader than the user-facing trigger model elsewhere in the file. Because the skill also pulls attendee, email, and relationship context, this can cause unintended processing of sensitive data for routine or private events the user did not explicitly ask to analyze.

Vague Triggers

Medium
Confidence
84% confidence
Finding
Several trigger phrases are ordinary conversational statements such as 'Meeting starting now' or 'I have a call in 30 minutes,' which increases the chance of accidental invocation during normal chat. In this skill, accidental activation is more risky because it can start note-taking workflows or initiate sensitive meeting-prep retrieval using calendar and communication history.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The pre-meeting brief features rely on accessing sensitive sources including calendar metadata, attendee identities, relationship history, and recent email threads, but the skill description does not clearly warn users about that access up front. This creates an informed-consent and privacy-risk issue, especially because the information collected may include confidential business relationships and prior communications.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill describes storing internal summaries in memory and using them automatically for future briefs, but it does not clearly disclose retention duration, deletion controls, or the sensitivity of long-term meeting records. Persistent storage of meeting notes, decisions, and commitments can expose highly confidential internal or client information if retained too broadly or surfaced unexpectedly later.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.