Back to skill

Security audit

meeting-memory

Security checks across malware telemetry and agentic risk

Overview

This skill has a coherent meeting-memory purpose, but it can send and persist meeting content in an external BlueColumn service without clear consent, retention, or sensitivity guidance.

Install only if you are comfortable with meeting notes and recall queries being sent to BlueColumn for persistent storage. Before using it, confirm what data may be stored, who can access it, how it can be deleted, and avoid secrets, regulated data, or confidential meetings unless your organization has approved that use.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is broad enough to encourage invocation in routine note-taking or meeting-assistant scenarios without strong scoping boundaries. In this context, that can cause an agent to send meeting content to an external persistent memory service even when the user did not explicitly request storage or cross-session recall, increasing the chance of unintended data disclosure.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill instructs agents to transmit meeting notes and queries to a third-party persistent memory service but does not clearly warn that potentially sensitive meeting content will leave the local context and be stored externally. Because meetings commonly contain confidential business, personal, or regulated information, silent transmission to persistent external storage creates a significant privacy and compliance risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.