Back to skill

Security audit

MeetGeek

Security checks across malware telemetry and agentic risk

Overview

This appears to be a disclosed MeetGeek skill for retrieving meeting information through a connected account, with no evidence of hidden or destructive behavior.

Install only if you are comfortable giving the skill access to retrieve MeetGeek meeting data from your connected account. Be mindful that meeting summaries and transcripts may contain sensitive business or personal information, and use the skill only for explicit MeetGeek data requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger text is overly broad because it instructs the agent to use this skill for ANY MeetGeek-related request, without narrowing to specific safe operations or requiring intent verification. That can cause unintended invocation in situations where MeetGeek is only tangentially mentioned, increasing the chance of unnecessary data access or disclosure from a connected third-party account.

VirusTotal

48/48 vendors flagged this skill as clean.

View on VirusTotal