Back to skill

Security audit

Granola

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Granola meeting-notes integration that uses Maton authentication to read meeting summaries, notes, and transcripts with clear credential and authorization cautions.

Install this only if you want an agent to access your Granola meeting content through Maton. Prefer OAuth, review which Granola account and scopes you authorize, require confirmation before creating new connections or any modifying operation, and remember that retrieved meeting notes, private notes, attendees, and transcripts may contain confidential business or personal information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The tool description explicitly states it returns private notes and other sensitive meeting data, but provides no user-facing warning, sensitivity labeling, or access-boundary reminder. In an agent setting, this increases the risk that the tool is invoked in response to casual prompts or by a user who does not understand that highly sensitive content may be retrieved.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.