Back to skill

Security audit

Cn Meeting Minutes

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow local meeting-minutes generator that reads user-provided meeting text and writes a Markdown report, with no hidden network, persistence, credential, or privilege behavior found.

Install this if you want a Chinese-language, local-only meeting-minutes helper. Be careful when processing meeting files from untrusted sources, and open generated Markdown in a viewer that disables raw HTML and automatic remote-resource loading if the input may be adversarial.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/meeting_minutes.py:166
Finding

Untrusted Meeting Content Is Written to Markdown Without Escaping

Content
View full analysis
Remediation
View remediation
`, and HTML entities if generated reports may be opened in renderers that support embedded HTML. 3. Consider implementing a dedicated helper that applies the same sanitization policy to every dynamic field: ```python def escape_markdown(value: object) -> str: text = str(value) text = text.replace("&", "&") text = text.replace("<", "<").replace(">", ">") return re.sub(r'([\\`*_{}\[\]()#+.!|~-])', r'\\\1', text) ``` 4. Apply the helper at the output boundary rather than relying only on extraction logic: ```python safe_topic = escape_markdown(topic) minutes += f"- **Meeting topic**: {safe_topic}\n" for point in key_points: minutes += f"- {escape_markdown(point)}\n" ``` 5. If links must be preserved, use an allowlist-based sanitizer that permits only explicitly required Markdown constructs and safe URL schemes. 6. Document that generated reports contain data derived from the input file and recommend opening them in a renderer configured to disable raw HTML and automatic remote-resource loading. 7. Add regression tests using remote-image syntax, HTML tags, nested links, headings, block quotes, and multiline payloads to ensure they are rendered as inert text. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring presents the tool name, description, and usage entirely in Chinese, and the rest of the script continues with Chinese-only prompts and output. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the restriction is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language content of the skill documentation is presented only in Chinese, including the description and usage sections. Under the stated policy, forcing a specific language without user opt-in can be a language/locale policy violation unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.