Back to skill

Security audit

Paper Club Pilot

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed meeting-assistant workflow for academic group meetings, with privacy-sensitive meeting capture that appears purpose-aligned and user-authorized.

Before installing, make sure your group is comfortable with meeting transcripts, participant-linked action items, and summaries being processed and stored in an academic knowledge base. Disable the local method-tag optimization logging if you do not want any post-use usage labels retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The manifest describes a skill for preparing, recording, and distilling research group meetings. However, the installation notice says the skill automatically records 'method-level tags' after each use for ongoing optimization, which is a meta-telemetry capability unrelated to the user-facing academic meeting workflow.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The manifest description at L006 limits the skill to pre-meeting recommendations, in-meeting smart notes, and post-meeting knowledge-base distillation. L020 adds a separate behavior: automatic recording of usage-derived labels for continual optimization, which is not part of the described meeting lifecycle behavior.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The markdown describes pulling Tencent Meeting smart notes/transcripts, extracting decisions and action items, using participant information, and storing distilled results in a knowledge base. Although it mentions confirming user authorization for meeting data access, it does not provide a clear user-facing warning that meeting content and attendee-linked actions may affect other participants' privacy and be archived.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.