Back to skill

Security audit

AI Meeting Notes w/ Action Items + To-Do List Tracker

Security checks for vulnerabilities and agentic risk

Overview

This meeting-notes skill is useful and mostly purpose-aligned, but it stores complete raw meeting content by default while also claiming nothing is stored.

Review before installing if you handle confidential meetings, customer data, HR/legal topics, financial details, or credentials in notes. Use it only in workspaces you trust, explicitly ask for no-save or summary-only handling when needed, and manually redact sensitive raw transcript content before sharing saved files or Slack-ready summaries.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:110
Finding

Automatic Plaintext Retention of Sensitive Meeting Content Without Explicit Consent

Content
View full analysis
📝 Raw Notes (click to expand) [Preserve the original input exactly as pasted] ``` From `SKILL.md:639-643`: ```markdown If user just wants to see the output (not save), show it in their requested format. If user wants both, save the file AND display the output. **Default behavior:** Save the file, offer to-do list prompt, then display summary. ``` From `SKILL.md:979-980`: ```markdown **Q: What about privacy?** Your notes are processed in the conversation. Nothing is stored or sent elsewhere. ``` ### Technical Analysis The skill directs the agent to save meeting content automatically and to preserve the complete original input in plaintext. Meeting transcripts can contain personal information, customer records, financial discussions, business plans, access details, or accidentally pasted credentials. The prescribed implementation provides no requirement for: - Explicit consent before persistence - Secret o ...[truncated 2566 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The AI instructions explicitly require saving the original input exactly as pasted in a 'Raw Notes' section. This creates a strong re-disclosure channel because any secrets, personal data, legal details, or confidential discussion included in the original notes are intentionally retained verbatim and can later be surfaced again.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions require preserving the original meeting input exactly as pasted inside the saved file, but there is no prominent warning that sensitive raw transcript content will be retained verbatim. Because meeting transcripts often contain names, contact details, strategic discussions, and other sensitive material, exact retention significantly raises exposure in case of later search, sharing, or accidental disclosure.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill requires attaching a full file containing everything, including raw notes, in the same response. That amplifies exposure by re-presenting sensitive user content in plain language and making it easier to copy, forward, or accidentally disclose beyond the original extraction context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly claims in the FAQ that notes are 'processed in the conversation' and 'nothing is stored or sent elsewhere,' yet earlier instructions require automatic saving of meeting notes and to-do data into workspace files. This is a material mismatch between documented privacy expectations and actual behavior, which can cause users to disclose sensitive meeting content under false assumptions about retention.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The privacy FAQ directly contradicts the rest of the skill, which repeatedly instructs the agent to auto-save notes, attendees, action items, and raw input. That contradiction is dangerous because it undermines informed consent and can lead to retention of confidential business discussions, personal data, or transcripts users believed would remain ephemeral.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that every extraction is automatically saved for future reference, but it does not prominently warn users before they paste potentially sensitive meeting notes. In this context, users are likely to include confidential project details, personnel issues, customer data, or internal decisions, so silent retention increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is designed for productivity, but instructing the agent to save original notes, attendees, and raw input creates a broad natural-language data retention surface. Even without malicious intent, this increases the chance that sensitive meeting content is later exposed through workspace access, follow-up queries, or file sharing.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The cross-file search feature allows retrieval of prior decisions and action items associated with named individuals from saved meeting files. In a meeting-notes skill this functionality is expected, but without access controls or privacy boundaries it can disclose historical conversational data more broadly than users may anticipate.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions to search all saved files for a person's name and return associated items with dates and source files enable person-specific profiling from accumulated meeting data. While useful for task tracking, this becomes dangerous when sensitive HR, legal, performance, or customer-related discussions are stored and can be retrieved by simple natural-language queries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example output encourages saving full meeting notes, transcripts, attendee names, customer issues, hiring details, and an ongoing to-do list to local files without any privacy, retention, or sensitivity warning. Meeting artifacts commonly contain confidential business data and personal information, so normalizing automatic storage increases the risk of inadvertent long-term exposure, oversharing, or unsafe handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Slack-ready example presents a polished summary suitable for reposting into chat channels, including customer issues, hiring status, budgets, and named individuals, but gives no warning about audience scope or confidentiality. This can lead users to paste sensitive internal summaries into broad or external Slack channels, causing accidental disclosure of business-sensitive or personal information.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The quick command "show todos" is a generic natural-language phrase that could easily appear in ordinary conversation, making activation scope ambiguous in a markdown-described skill. The file does not provide constraints, exclusion conditions, or a narrower invocation context to clarify when this phrase should trigger the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The phrase "what's overdue?" is a common conversational question and is not sufficiently distinguished from everyday speech. The markdown does not specify whether this only works within a to-do context or how the system avoids unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.