Back to skill

Security audit

会议记录助手

Security checks for vulnerabilities and agentic risk

Overview

This meeting-notes skill is a simple, coherent Markdown-only skill, but users should understand that it stores meeting notes and action items persistently.

Install only if you are comfortable with meeting notes and action items being written to local JSON files. Avoid using it for highly confidential meetings unless you have confirmed where those files are stored, who can access them, and how to delete or redact records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents the skill name, description, tags, headings, and examples entirely in Chinese, with no indication that users can select another language or that the skill is intended only for a Chinese-speaking or region-specific environment. This creates a language/locale constraint in natural-language content without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger section lists generic phrases such as “记录会议”, “会议记录”, “查看会议”, and “搜索会议” without clarifying boundaries, exclusions, or the context in which the skill should activate. Because these are common phrases in ordinary conversation and no negative examples or scope constraints are provided, the skill could be invoked unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly stores meeting records and action items persistently, but gives no notice about retention, sensitivity, access controls, or privacy implications. Because meeting notes often contain confidential business discussions, participant identities, and task ownership, silent persistence can expose sensitive data to unintended retention or later access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.