Back to skill

Security audit

AI Meeting Notes w/ Action Items + To-Do List Tracker

Security checks across malware telemetry and agentic risk

Overview

This skill does what it advertises: turns pasted meeting text into local saved notes and todos, but users should understand that raw notes can persist in workspace files.

Install only if local persistence is acceptable. Pasted notes may be saved verbatim under meeting-notes/, selected tasks may be written to todo.md, and prior notes may be searchable in later sessions. Use a private workspace, redact sensitive transcripts before processing, and periodically review or delete saved files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The skill's FAQ tells users that 'nothing is stored,' but the instructions elsewhere explicitly save meeting notes and todos to workspace files. This is a material privacy misrepresentation that can cause users to paste sensitive transcripts or internal discussions under false assumptions about retention.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises that every extraction is 'automatically saved' but does not prominently warn users in the primary flow that pasted meeting content will be written to local files. Meeting notes often contain confidential business, HR, legal, or personal data, so silent persistence increases the risk of unintended disclosure.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill states that raw notes are preserved in saved files, but does not pair that behavior with an explicit privacy warning or minimization guidance. Preserving verbatim input can capture secrets, personal data, legal strategy, or credentials embedded in transcripts, expanding the blast radius beyond the summarized output.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The AI instructions mandate creating folders and files in the workspace as part of normal operation without a user-facing consent step in the main workflow. Silent file creation can surprise users and leave sensitive meeting artifacts accessible to later sessions, tools, or collaborators with workspace access.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The example repeatedly shows automatically saving raw meeting notes, attendee names, customer issues, hiring details, budgets, and operational discussions into persistent markdown files without any warning, minimization, or redaction guidance. Meeting notes often contain sensitive business or personal data, so normalizing storage of full transcripts and notes can lead to unintended retention and later disclosure.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The Slack-ready example encourages reposting meeting content—including customer issues, budget approvals, staffing details, and file paths—into an external/shared communication channel without any sensitivity check or warning. If used with real data, this can broaden access to confidential information beyond the original meeting audience and create secondary disclosure and retention risks in Slack.

Ssd 3

Medium
Confidence
94% confidence
Finding
Instructing the system to save all raw user-provided meeting content verbatim creates unnecessary long-term retention of potentially sensitive information. This increases exposure if the workspace is later searched, shared, synced, or accessed by other skills or users.

Ssd 3

High
Confidence
98% confidence
Finding
The instructions explicitly require preserving the original pasted input 'exactly' in saved files, which can retain confidential or regulated content without filtering. Exact preservation also defeats opportunities to strip secrets or irrelevant personal data before persistence.

Ssd 3

Medium
Confidence
91% confidence
Finding
The skill encourages searching prior saved meeting files and returning results across sessions, which creates a cross-session disclosure surface for previously stored sensitive notes. Even if intended as a productivity feature, it can expose confidential historical content more broadly than users expect.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.