Back to skill

Security audit

google-meet

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Google Meet integration that uses Maton OAuth/API tooling and includes broad platform reference material, but its risky actions are documented with user-approval and scoping requirements.

Install only if you intend to use Maton for Google Meet. Review carefully before approving connections, hosted functions, triggers, destinations, or raw API key use, because those can persist and may forward sensitive meeting or event data if you authorize them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Google Meet skill bundles detailed Calendly trigger documentation and payload schemas, including third-party PII and meeting join URLs, which broadens the effective operational surface and can mislead an agent into handling unrelated data sources under the wrong skill context. Even though the text says it is only shared reference material, embedding actionable event types, payloads, and forwarding guidance in the skill increases the chance of unintended cross-source data access, disclosure, or misuse in downstream automations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file claims it does not widen the skill's scope, but it then provides concrete Calendly event behavior and sensitive payload examples containing personal data fields and join URLs. That mismatch can create false trust boundaries for agents or users, causing them to underestimate the sensitivity and applicability of the included content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The Google Meet manifest says the reference files under references/<source>/triggers.md are platform event catalogues that do not add Google Meet capability, and specifically that Google Meet is not an event source. This file's line-level documentation nevertheless instructs the reader to use the file when a user has connected Linear and wants to act on Linear events, which conflicts with the parent skill's claimed Google Meet-only scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.