Back to skill

Security audit

Call-Transcript-Todo

Security checks across malware telemetry and agentic risk

Overview

This skill has a clear transcription purpose, but it may send sensitive call transcripts to Feishu automatically when credentials are present.

Install only if you are comfortable with recordings and derived transcripts being saved. Before using it, decide whether output should stay local or go to Feishu, check who can access the Feishu destination, and avoid using it for regulated or highly confidential calls unless you add an explicit confirmation/redaction step.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill handles potentially sensitive call recordings, transcripts, summaries, and extracted action items, then stores them to Feishu or local Markdown files without requiring an explicit privacy notice, consent checkpoint, or confirmation of the storage destination. This can lead to unintended disclosure of personal, business, or regulated information, especially because the workflow encourages persistence and optional syncing to a third-party platform.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.