Back to skill

Security audit

培训纪要结构化手册

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently turns training meeting transcripts or minutes into a structured handbook, with sensitive meeting access aligned to that purpose.

Install only if you are comfortable letting the agent process the selected Tencent Meeting training transcript or minutes. Use a specific meeting ID or local file you are authorized to access, and review generated handbooks before sharing them because they may contain internal training content.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill states it will pull meeting transcripts and smart minutes via tmeet, but it does not prominently disclose that this may access potentially sensitive meeting recordings, internal training content, and participant-generated data. In enterprise settings, this can lead to unanticipated processing of confidential materials or user surprise about the scope of access, increasing privacy and compliance risk.

Static analysis

No suspicious patterns detected.