Ae1
High
- Category
- analysis-evasion
- Content
| "Show meeting details" | `query_meetings.js` |
- Confidence
- 100% confidence
- Finding
- Referenced artifact was not completely inspected
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it claims, but it can use enterprise Tencent Meeting credentials to create meetings and access recordings/transcripts with broad triggers and limited consent warnings.
Install only if you intend this skill to use Tencent Meeting enterprise API credentials. Treat transcript and recording operations as sensitive: confirm the meeting, user ID, authorization, and sharing destination before retrieving or exposing download URLs or transcript text.
| "Show meeting details" | `query_meetings.js` |
| "Download meeting recording" | `list_records.js` → use download URLs |
Detected: suspicious.env_credential_access