Back to skill

Security audit

Meetlark - coordinate a meeting

Security checks across malware telemetry and agentic risk

Overview

Meetlark is a straightforward scheduling-poll skill that uses the Meetlark service, with manageable privacy and token-handling considerations.

Install this only if you are comfortable using Meetlark as an external scheduling service. Treat admin tokens and individual vote results as sensitive, share only the participation URL with invitees, and clear stored admin tokens after the poll is closed or no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to collect meeting times, email status, participation links, and poll data from users and send them to an external service, but it does not warn users that their scheduling and participant information will leave the local assistant context. This can lead to unintended disclosure of personal, organizational, or relationship metadata, especially because admin tokens and individual voting results are involved.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.