MeetGeek

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward MeetGeek CLI helper, but it can expose sensitive meeting data through a configured API key.

Install only if you trust the meetgeek-cli npm package and want this environment to access your MeetGeek account. Treat transcripts, summaries, and exported files as confidential, avoid saving them in shared or temporary locations when they contain sensitive content, and clear the saved API key when access is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This skill is designed to retrieve highly sensitive meeting content, including transcripts, summaries, speaker-attributed notes, and action items, but the documentation provides no warning about confidentiality, data handling, or safe storage/export practices. That omission can lead users to expose internal business discussions or personal data by exporting transcripts to insecure locations, sharing output in other tools, or using the skill in environments without appropriate access controls.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal