Back to skill

Security audit

Meetings

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local meeting assistant, but it automatically edits long-lived meeting, contact, and project notes and records behavioral details about people without a clear approval step.

Install only if you are comfortable with a local skill maintaining meeting memory plus shared contact and project notes. Before using it in real workplaces, require explicit confirmation before writes or deletions, avoid storing subjective comments about people, keep sensitive HR/legal/health/compensation content out of these files, and back up the local data stores.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document claims sensitive personnel and compensation content is never written to disk, but later directs writing durable interpersonal context, conflict handling traits, pain points, and facilitation artifacts to persistent files. Even if some categories are excluded, these records can still contain sensitive behavioral and workplace-relations data that may expose private employment information or enable misuse, especially when linked to named individuals.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · difficult.md (reported line 59)May include surrounding context.

md
## Saying No

- **No, then the reason, then the alternative** — in that order. A reason before the no reads as negotiable, and the other person spends it arguing with the reason.
- **Trade, do not refuse flatly, when the request is legitimate**: "yes, and it moves X by two weeks — your call which." That sentence converts a refusal into a decision the requester owns.
- **Never say no to a scope change live in a client meeting.** "That's a change — I'll come back today with what it costs and what it moves" (`external.md`).
- **No to a person with power over the work is a reshape, not a refusal**: ask for the priority call, offer the smaller version, name what drops.
- **A soft no is a slow yes.** "I'll see what I can do" with no intention behind it costs the relationship more than the clear no would have.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · difficult.md (reported line 60)May include surrounding context.

md
- **No, then the reason, then the alternative** — in that order. A reason before the no reads as negotiable, and the other person spends it arguing with the reason.
- **Trade, do not refuse flatly, when the request is legitimate**: "yes, and it moves X by two weeks — your call which." That sentence converts a refusal into a decision the requester owns.
- **Never say no to a scope change live in a client meeting.** "That's a change — I'll come back today with what it costs and what it moves" (`external.md`).
- **No to a person with power over the work is a reshape, not a refusal**: ask for the priority call, offer the smaller version, name what drops.
- **A soft no is a slow yes.** "I'll see what I can do" with no intention behind it costs the relationship more than the clear no would have.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs writing observations about how a person responds to chases back into their contact record, effectively building behavioral profiles in the address book. This is a stronger violation than read-only access because it creates persistent personal metadata unrelated to core meeting execution and can cause privacy, accuracy, and misuse issues over time.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · meeting-load.md (reported line 65)May include surrounding context.

md
| Convert to async | Purpose is `review` or `status` | "Sending my input in the doc by Thursday — let's meet only if the comments deadlock." |
| Decline outright | No output named after asking once | "What would we decide? If it's an update I'd rather read it." |

Two rules that keep this from costing political capital: **decline in advance, never by no-show**, and **never decline the same series twice without renegotiating it** — the third silent decline is read as contempt, while "this meeting isn't working for me, can we change it" is read as engagement.

If the invite comes from someone with power over the user's work, the play is not declining, it is reshaping: ask for the agenda, offer to own an item, propose the shorter slot. Getting the agenda written is often the whole fix.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file asserts that writes and deletions stay inside declared configPaths, but the documented behavior includes modifying shared boxes outside that boundary. This contradiction undermines safety controls and can cause enforcement bypasses if reviewers or runtime guards trust the narrower declaration while the skill operationally writes elsewhere.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation presents a safety boundary ('writes and deletions stay inside declared configPaths') and then requires modifications to shared contacts and project files beyond that boundary. This is dangerous because it encourages operators and tooling to rely on a false containment guarantee, increasing the chance of unauthorized file modification and corruption of shared data used by other skills.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section explicitly directs writing persistent attendee behavior notes into contacts data, turning transient meeting observations into durable person records. That is dangerous because it enables long-lived profiling of communication style and participation habits, which may be inaccurate, sensitive in context, and reused in ways unrelated to the original meeting purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description lists a very wide range of ordinary workplace scenarios such as meetings that 'run long,' 'action items vanish,' or when 'a recap or formal minutes have to go out.' For a manifest/markdown-style skill description, this scope is broad enough that many routine conversations about work could match, without explicit trigger constraints or negative examples beyond a few adjacent skills.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs creation of reusable scripts, failure-pattern archives, and behavioral context about individuals, which goes beyond documenting meeting outcomes into building interpersonal playbooks. Such artifacts can be repurposed for manipulation, bias reinforcement, or undocumented personnel tracking without the subject's knowledge.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file instructs storing how a person handles conflict, news, or pressure in a contacts repository, creating a long-term behavioral profile unrelated to basic meeting logistics. This expands the skill from facilitation into persistent profiling of employees or contacts, which creates privacy, fairness, and insider-misuse risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document tells the operator to write interpersonal context about named people to disk but does not require any user-facing notice, consent, or privacy warning. Persisting subjective observations about how someone reacts under pressure can create hidden surveillance-like records and expose the organization to privacy and employment-risk issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs broad writes to multiple local files containing meeting records, contacts, follow-ups, decisions, and board artifacts in the same turn, but does not require user confirmation or clearly warn that local data will be modified. In an agent setting, this can cause unintended persistence, overwrite sensitive records, and spread potentially inaccurate or confidential external-meeting data across several ledgers.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill goes beyond meeting facilitation and instructs persistent recording of attendee-specific behavioral information into contact profiles and organizational memory stores. That creates unnecessary collection and retention of personal inferences tied to individuals, which can be misused for profiling, bias, or secondary purposes unrelated to the immediate meeting task.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to write 'anything you learned about how a person operates in the room' into persistent contact records authorizes ongoing behavioral profiling without clear necessity for meeting execution. Because these notes are durable and person-linked, they can influence future treatment of attendees, leak sensitive workplace judgments, and expand the skill into people-management surveillance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs silent persistence of attendee behavioral observations into a contacts database with no user-facing notice, consent check, or privacy boundary. This is dangerous because users may unknowingly create sensitive, subjective records about coworkers or clients, increasing privacy, compliance, and trust risks in a context where participants would expect facilitation help, not hidden dossier-building.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs reading from the contacts/address-book store to tailor how follow-up messages should be phrased. That exceeds the manifest boundary that says this skill is not for the address book itself, creating unnecessary cross-domain access to personal data and increasing privacy and scope-creep risk.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · external.md (reported line 81)May include surrounding context.

md
| **Owner**, one named person | A team owner is nobody's Monday morning | Can you address a message to it? |
| **Verb + object** | "Look into pricing" ends when attention does | Does it name a produced thing? |
| **Date**, absolute | "Next week" drifts a week per week | Is it a calendar date, not a relative one? |
| **Done means** | Two people disagree about whether it closed | Could a third party mark it done without asking? |

- **`Done means` is what makes an item closeable by someone other than its author** — the sweep can only verify what was defined. "Vendor comparison" → "table in the channel, three options with prices".
- **Absolute dates only.** "By Thursday 30 Jul" is verifiable four weeks later; "next week" is not. If the owner will not commit to a date, the real answer is that it is not going to happen — record that instead of a fake date.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · follow-through.md (reported line 16)May include surrounding context.

md
| **Owner**, one named person | A team owner is nobody's Monday morning | Can you address a message to it? |
| **Verb + object** | "Look into pricing" ends when attention does | Does it name a produced thing? |
| **Date**, absolute | "Next week" drifts a week per week | Is it a calendar date, not a relative one? |
| **Done means** | Two people disagree about whether it closed | Could a third party mark it done without asking? |

- **`Done means` is what makes an item closeable by someone other than its author** — the sweep can only verify what was defined. "Vendor comparison" → "table in the channel, three options with prices".
- **Absolute dates only.** "By Thursday 30 Jul" is verifiable four weeks later; "next week" is not. If the owner will not commit to a date, the real answer is that it is not going to happen — record that instead of a fake date.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill repeatedly instructs deleting rows, re-dating items, and writing closures into persistent records, but provides no requirement to notify the user or confirm before modifying files. Autonomous mutation of durable records can lead to silent data loss, inaccurate audit trails, or unwanted changes that are hard to reconstruct.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to write audit results into persistent meeting memory files as part of normal execution, but it does not require explicit user awareness or confirmation before modifying those files. This creates a state-persistence risk: the agent may silently alter long-lived records, propagating mistakes or unwanted changes across future interactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This instruction mandates writing back changes to multiple files in the same turn after audits, declines, or async replacements, again without an explicit confirmation step. Automatic multi-file persistence increases the blast radius of errors and makes it easy for an agent to overwrite organizational records without the user's informed consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs writes to shared data stores outside the meetings namespace (contacts and projects). That creates cross-skill data integrity and scope-boundary risk: a meetings-focused skill can alter broader user data, and mistakes or prompt injection in meeting content could propagate into unrelated shared records.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs reading person-specific data from multiple private files and then using it to create or update prep artifacts. This creates a data minimization and retention risk because personal context, obligations, and behavioral notes can be recopied into additional long-lived documents, increasing exposure and making unintended disclosure more likely.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file directs the model to write new observations about how a person operates into a persistent contacts file. Storing subjective behavioral notes and meeting-derived personal context in a long-lived record can create privacy, profiling, and misuse risks, especially if later surfaced in unrelated contexts or accessed by unintended readers.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.