Back to skill

Security audit

Meetings

Security checks across malware telemetry and agentic risk

Overview

This meeting-management skill stores meeting records and attendee context locally, but that behavior is disclosed, scoped, and aligned with its purpose.

Install only if you want a meeting assistant that maintains durable local meeting memory. Review the shared contacts/projects behavior, set confidentiality preferences, and avoid using it to store HR, legal, compensation, health, or subjective performance notes outside the proper system.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The file explicitly says compensation, ratings, health, and personnel content is never written to disk, but later instructs storing person-specific conflict handling traits and failure patterns in contacts and meeting artifacts. That contradiction can cause an agent or operator to persist sensitive interpersonal and personnel-adjacent data despite a stated prohibition, creating privacy, HR, and legal exposure.

Intent-Code Divergence

High
Confidence
93% confidence
Finding
The personnel section says 'Nothing goes to disk' for sensitive employment matters, yet the 'After' section and final write instructions mandate creating records, follow-ups, contact context, pain points, and reusable scripts from hard conversations. In context, those outputs are likely to capture sensitive details or strong inferences about employees and stakeholders, defeating the stated safeguard and encouraging broad retention of sensitive meeting data.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The instruction to write 'anything you learned about how a person operates in the room' into persistent contact records goes beyond meeting execution and creates an ongoing behavioral dossier on attendees. That expands data collection into profiling without any stated consent, minimization, retention, or access-control guidance, which can expose sensitive interpersonal judgments and be misused in later contexts unrelated to the meeting.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
This guidance explicitly captures personal behavioral profiling and stores it in a general contacts file, despite the skill being described as meeting design and facilitation. In context, that makes the issue more concerning because the data collection is not necessary for the core function and risks normalizing covert accumulation of subjective personnel intelligence.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill explicitly directs writes into shared `contacts` and `projects` stores outside the meetings data area. That expands its write scope beyond its own namespace and can let a meetings workflow modify cross-skill data, increasing the chance of unintended data corruption, privacy leakage, or lateral impact on other skills that trust those files.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The template claims writes and deletions remain inside the skill's declared paths, but later instructs updates to shared contacts and project locations outside that boundary. This policy contradiction is dangerous because agents or reviewers may rely on the narrower promise while the actual behavior grants broader filesystem influence, enabling unauthorized modification or deletion of shared data.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The instruction to add new attendees to `~/Clawic/data/contacts/contacts.md` causes the Meetings skill to modify an address-book style data store that the skill description explicitly says is out of scope. Cross-skill writes like this can bypass intended separation of responsibilities, leading to unintended persistence of personal data, stale or incorrect contact records, and expansion of the skill's authority beyond what a user would reasonably expect from a meetings-only tool.

Missing User Warnings

Low
Confidence
89% confidence
Finding
The instruction explicitly tells the agent to write artifacts into persistent local storage under ~/Clawic/data/meetings without any user confirmation or warning that stored data will be created or modified. In a meeting-management skill this is contextually relevant, but it still creates a safety issue because the agent may persist potentially sensitive organizational information or alter existing records unexpectedly.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs reading and consolidating external parties' contact details, roles, challenges, meeting history, and project context from multiple files, but provides no privacy, confidentiality, minimization, or access-control guidance. In a meetings skill handling clients, vendors, investors, and boards, this can lead to over-collection, unnecessary propagation of sensitive third-party personal/business data, and accidental disclosure in recaps or internal records.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill directs broad same-turn writes of meeting content into numerous long-lived stores, including records, decisions, follow-ups, contacts, project files, board minutes, and prep artifacts, while capturing verbatim commitments, complaints, blockers, and new people metadata. This creates a significant risk of excessive retention, cross-context leakage, and durable storage of sensitive or legally discoverable information without any warning, consent check, retention policy, or need-to-know filtering.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The file directs recording personal attendee observations into contact records with no privacy warning, no distinction between objective facts and subjective impressions, and no safeguards around sensitivity, access, or retention. That omission increases the chance of oversharing, bias memorialization, and secondary misuse of personal information by anyone who later reads the contact database.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs writing updates across several persistent user data files in the same turn, including meeting memory, records, contacts, and follow-up ledgers, without any confirmation or safety gate before modifying records. In an agent setting, this creates a real integrity risk: a mistaken parse, adversarial meeting content, or over-eager automation could silently alter multiple authoritative files and propagate incorrect state.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This instruction tells the agent to persist audit results into local memory files as part of normal execution, but the skill description does not clearly disclose that using it may modify files. Silent persistence is risky because a user may expect advisory output only, while the agent mutates long-lived state that can affect later decisions and workflows.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill directs the agent to write updates across multiple local files, including recording killed series, in the same turn. That creates persistent side effects beyond the immediate conversation and increases the chance of unintended or user-unapproved modifications to operational records.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.