Meeting Notes → Tasks & Follow-up

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward local meeting-notes helper with disclosed templates and scripts, and no evidence of hidden network access, credential use, or persistence.

Install if you are comfortable processing meeting notes locally with this skill. Use deliberate input and output paths, avoid overwriting important files, and remember transcripts may contain sensitive business or personal information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill instructs the agent to use local resources such as `references/templates.md`, `scripts/task_extractor.py`, and `scripts/meeting_summary.py`, which implies file read capability and likely file output generation, yet no permissions are declared. This creates a trust and containment problem: a caller may invoke what appears to be a text-only summarization skill, while the agent is actually encouraged to access bundled files and generate artifacts, increasing the attack surface and making unintended file access harder to audit.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal