Back to skill

Security audit

Meeting Notes Assistant

Security checks across malware telemetry and agentic risk

Overview

This looks like a real meeting-notes tool, but users should review it because it can send sensitive transcripts to external AI services despite strong offline/privacy wording.

Review the privacy tradeoff before installing. For confidential meetings, run with --no-llm, avoid setting OPENAI_API_KEY/OPENAI_API_BASE, and keep outputs in a secure local folder. If you enable LLM or cloud ASR features, assume transcript or audio content may be sent to the selected provider and governed by that provider’s retention and training policies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (35)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill documents shell execution, file read/write, and environment/config access, but no permissions are declared to bound or disclose those capabilities. That creates a trust and containment gap: users may assume a documentation-only meeting assistant while the implementation can access local files, configs, and invoke scripts with broader effects.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The manifest and description emphasize local/offline, privacy-safe meeting note generation, but the documented default path sends transcript content to external LLM APIs and includes additional behaviors beyond the stated scope. This mismatch can cause users to expose sensitive meeting content under false privacy assumptions and undermines informed consent.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The guide expands the advertised behavior from local/offline Whisper processing to include cloud transcription and Feishu-based document delivery, which changes the trust and data-flow model users rely on. This can mislead users into sharing sensitive meeting audio under false assumptions about locality and privacy, creating an integrity and privacy risk even if no exploit code is present.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The document presents the product as offline/privacy-safe while elsewhere encouraging cloud transcription, which is internally contradictory and can cause users to make unsafe choices with confidential recordings. In a meeting-notes skill, audio often contains business-sensitive or personal data, so inaccurate privacy claims materially increase exposure risk.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The plan states that note generation now prefers an OpenAI-compatible API with configurable base URL, API key, and model, which materially contradicts the skill description's promise of local/offline/private processing. This creates a real risk of silent data exfiltration of meeting transcripts and action items to remote LLM providers, especially in sensitive business or financial meetings where users may rely on the offline/privacy claim.

Context-Inappropriate Capability

Medium
Confidence
74% confidence
Finding
Finance-specific extraction increases sensitivity because the plan explicitly targets customer needs, product proposals, returns signals, and risk points from meeting content. In the context of the same document introducing configurable external LLM calls, this scope expansion makes unintended disclosure of regulated or highly confidential financial information more dangerous.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill metadata strongly markets the assistant as offline and privacy-safe, while the privacy document reveals optional cloud transcription and LLM parsing modes that send meeting audio or transcripts to third parties. This mismatch can mislead users into exposing sensitive meeting content under an incorrect assumption of fully local processing, which is especially risky for confidential business discussions.

Intent-Code Divergence

Low
Confidence
82% confidence
Finding
The document emphasizes a completely offline local mode, but the overall skill description omits that other documented modes require network access and third-party processing. Users may therefore rely on the high-level description and miss material privacy differences between modes, leading to accidental disclosure of meeting data.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill claims local/offline, privacy-safe processing, yet the workflow later states that transcript content is sent to external LLM APIs by default. For meeting notes, transcripts often contain confidential business, legal, HR, or customer data, so this contradiction materially increases the risk of unintended data disclosure.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill claims local/offline, privacy-safe processing, yet the workflow later states that transcript content is sent to external LLM APIs by default. For meeting notes, transcripts often contain confidential business, legal, HR, or customer data, so this contradiction materially increases the risk of unintended data disclosure.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The documentation repeatedly says the tool is 'completely offline' and requires no network, while other sections describe automatic model downloads and default transmission of transcripts to remote LLM APIs. This is a strong deceptive or at least misleading privacy claim that can lead users to process confidential recordings they would not otherwise upload.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The design document explicitly broadens the skill from a meeting-notes assistant into a cross-industry, effectively general-purpose transcription and summarization platform. This scope expansion can bypass user and platform expectations, increasing the chance the skill is used for unintended data processing scenarios involving sensitive audio and domain-specific content.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The concluding claim that this is a 'general meeting transcription and summary platform' reinforces a material mismatch between the declared assistant purpose and its documented behavior. Such mismatch is risky because reviewers or users may grant trust to a narrower meeting-notes tool while the implementation is being positioned as a broader, more capable processing system.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill description emphasizes offline, privacy-safe processing, but the code is explicitly wired to use a remote LLM endpoint by default when valid configuration is present. Because meeting transcripts often contain sensitive business, financial, and personal information, silently sending them to a third-party API creates a confidentiality and trust-boundary violation.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The skill presents processing as '完全免费,隐私安全,数据不上云' while also warning that first use may download model files. Even if audio is not uploaded, undisclosed outbound network activity undermines the privacy claim and can mislead users operating under strict offline or data-handling assumptions.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill advertises local, offline, privacy-safe Whisper transcription, but this code can trigger a runtime download of the large-v3 model from a remote URL. That breaks the offline/privacy expectation and may leak metadata such as IP address, usage timing, and model selection, while also introducing supply-chain and reliability risks if users assume no network access occurs.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The guide recommends a cloud transcription option without a prominent warning that meeting audio will be uploaded to a remote service. Because meeting recordings commonly contain confidential business discussions, personal data, or regulated information, lack of informed consent and disclosure significantly raises privacy, compliance, and data-handling risk.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Treating any direct file or link upload as a trigger without scope constraints can cause the skill to ingest arbitrary local or remote content, including sensitive documents or untrusted URLs. In a note-taking assistant that also supports external APIs and exports, ambiguous activation increases the chance of unintended data processing or exfiltration.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The guide instructs users to configure Tencent or Aliyun ASR and send meeting audio to those providers, but does not warn that potentially confidential recordings and derived transcripts may leave the local environment. In a meeting-notes skill, this is especially sensitive because recordings often contain business, legal, HR, or customer data, so users may unknowingly violate privacy or compliance expectations.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The output section lists transcript, summary, key-term, and action-item files written to disk without warning that these artifacts can contain highly sensitive meeting content, names, decisions, and deadlines. In this skill's context, local files may persist unencrypted, be synced to cloud storage, indexed by desktop search, or be accessible to other users on the machine, increasing confidentiality risk.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The document describes persisting user custom dictionaries under a local working-directory path without any notice, consent flow, retention policy, or safety constraints. Writing user-provided terms to disk can create unexpected data residue, especially if the terms contain confidential names, projects, clients, or regulated terminology extracted from meetings.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The code sends transcript content to an external LLM API during normal operation but does not present a user-facing warning or confirmation at the point where transmission occurs. For a meeting-notes assistant handling potentially confidential recordings, this lack of informed consent materially increases privacy and compliance risk.

Ssd 3

Medium
Confidence
97% confidence
Finding
The raw transcript is inserted nearly wholesale into the LLM prompt, which can disclose entire conversations, names, business plans, and financial details to the model provider. In this skill context, that is especially sensitive because meeting notes often include confidential corporate discussions and regulated financial information.

External Transmission

Medium
Category
Data Exfiltration
Content
```json
{
  "llm_base_url": "https://api.openai.com/v1",
  "llm_api_key": "sk-your-key-here",
  "llm_model": "gpt-4o-mini"
}
Confidence
90% confidence
Finding
https://api.openai.com/

External Transmission

Medium
Category
Data Exfiltration
Content
国内兼容接口示例(通义千问、DeepSeek、智谱等):
```json
{
  "llm_base_url": "https://api.deepseek.com/v1",
  "llm_api_key": "sk-your-deepseek-key",
  "llm_model": "deepseek-chat"
}
Confidence
90% confidence
Finding
https://api.deepseek.com/

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.