Coordinate a Meeting

Security checks across malware telemetry and agentic risk

Overview

This is a simple meeting-poll skill that uses MeetLark as advertised, with privacy considerations users should understand before sharing scheduling details.

Before installing, be comfortable sending meeting purpose, proposed times, participant-related details, and verification email information to meetlark.ai. Keep the admin token private and share the participation link only with intended voters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs the agent to create and distribute a scheduling poll through an external service, but it does not require any explicit notice that participant names, email addresses, availability, and meeting details may be sent to meetlark.ai. This can cause users to unknowingly disclose personal or organizational scheduling data to a third party, which is especially sensitive in workplace or client contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal