Otterai Cli

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Otter.ai CLI helper for working with meeting transcripts and recordings, with expected privacy-sensitive access but no evidence of hidden or malicious behavior.

Install only if you intend to let the agent use your Otter.ai account. Prefer `otter login` with keychain storage over persistent username/password environment variables, and confirm before uploads, downloads, trashing, moving, renaming, or speaker-tagging meeting content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill trigger is broad enough to activate on generic requests about meetings, recordings, or transcripts, which can route unrelated user tasks into a high-privilege integration that accesses Otter.ai data. In context, this increases the chance of unintended data exposure or actions against the user's Otter account when the user did not explicitly ask to use Otter.ai.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill documents downloading transcripts/files and uploading recordings without requiring explicit user confirmation or warning about external data transfer, local file creation, and potentially sensitive meeting content. Because Otter data commonly contains confidential business or personal information, silent upload/download behavior can cause privacy leaks or unexpected filesystem side effects.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal