Back to skill

Security audit

腾讯会议议章程管理&沉淀

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Tencent Meeting charter helper that saves user-directed meeting notes and optional one-time reminders without hidden execution or unrelated data access.

Install this if you are comfortable with the agent saving meeting-charter markdown files in your current workspace and creating explicit one-time reminders. Avoid using it with highly sensitive meeting materials unless that workspace is an authorized place to store them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt uses very broad activation language ('turn my files and conversation into a versioned meeting charter' and schedule reminders) without clear limits on when the skill should be invoked. This can cause over-triggering in unrelated conversations that mention files, reminders, agendas, or meeting prep, potentially leading to unnecessary access to user context and unintended persistence of conversation-derived content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.