Back to skill

Security audit

meetmind

Security checks for vulnerabilities and agentic risk

Overview

MeetMind is a cloud-backed meeting-minutes skill whose remote processing, user ID tracking, paid tiers, memory features, and template management are disclosed and aligned with its stated purpose.

Install only if you are comfortable sending meeting text or audio, user identifiers, usage data, and paid-tier memory context to the MeetMind cloud service. Avoid using it for confidential meetings unless your organization accepts the provider, retention model, analytics, and account-linking behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented behavior goes beyond a simple meeting-minutes assistant by persisting identifiers, transmitting identity and usage data to a remote service, and exposing template management operations. Even if these are product features, under-disclosure of tracking and account-related operations is security-relevant because users may provide sensitive meeting content without realizing the extent of identity linkage and remote account interaction.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior goes beyond a simple meeting-minutes assistant by persisting identifiers, transmitting identity and usage data to a remote service, and exposing template management operations. Even if these are product features, under-disclosure of tracking and account-related operations is security-relevant because users may provide sensitive meeting content without realizing the extent of identity linkage and remote account interaction.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises behaviors that require sensitive capabilities such as environment access, local file persistence, network calls, and possibly shell-adjacent execution, but it does not declare any explicit tool scope or permissions boundary. This weakens reviewability and informed consent, making it easier for a user or host platform to underestimate what the skill can access and do.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states it automatically obtains a WorkBuddy user ID and sends meeting text to cloud APIs, but it does not provide a clear privacy notice describing what data is collected, retention, sharing, or consent. Because meeting notes often contain confidential business, personnel, or customer information, silent transmission of identity-linked content to a remote service materially increases privacy and data leakage risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes analytics events and cross-meeting tracking tied to user_id without an explicit warning or consent step. This creates covert behavioral monitoring and longitudinal profiling risk, especially when combined with sensitive meeting content and persistent identifiers across sessions or devices.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest sets "language": "zh" as a fixed default/constraint, with no accompanying option for user selection or justification that the skill is intended only for a Chinese-specific deployment. The policy requires flagging natural-language locale constraints when the skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file’s natural-language documentation and user-facing strings are entirely in Chinese, with no indication that language is configurable or selected based on user preference. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The client automatically harvests identity from environment variables and persists a cross-session identifier to disk, creating silent user tracking beyond a single invocation. In a meeting assistant context that handles sensitive content, persistent identity linkage increases privacy risk and can enable unintended correlation of data across sessions or skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The client transmits a platform-derived user identifier in headers and sends meeting text/audio to a remote service without any built-in consent, warning, or confirmation in this code path. Because meeting notes and recordings commonly contain sensitive business or personal information, silent exfiltration to a third-party endpoint materially raises privacy and compliance risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes an assistant for converting text/audio into structured meeting notes and tracking cross-meeting memory. While template auto-recognition is mentioned, this code goes further by exposing full CRUD operations for user-defined templates against the cloud service, which is a broader management capability than the stated core note-assistant behavior.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/transcribe.py (reported line 25)May include surrounding context.

python
"""如果当前不在 meetmind-env 中,重新用 venv 执行"""
    if VENV_PYTHON.exists() and sys.executable != str(VENV_PYTHON):
        cmd = [str(VENV_PYTHON), __file__] + sys.argv[1:]
        result = subprocess.run(cmd, capture_output=False)
        sys.exit(result.returncode)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sets the default transcription language to "zh", which imposes a specific language/locale behavior unless the user explicitly overrides it. This is a natural-language policy concern because the tool does not present language choice by default or document an opt-in requirement in the execution flow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code writes a stable local user identifier to disk without notice or consent, enabling persistent tracking across runs. While lower impact than transmitting meeting content, this still creates unnecessary privacy risk and can surprise users who expect stateless processing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The docstring states '之后完全离线' while the implementation and error hint explicitly acknowledge that first-time model loading requires downloading the Whisper model. This is an intent/documentation contradiction about network behavior, even though it is limited to initial setup.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.