Security audit
meeting-scribe
Security checks across malware telemetry and agentic risk
Overview
This skill is a clearly scoped meeting-note helper that reads user-provided transcripts and entity files, writes local meeting memory, and explicitly avoids sending email or guessing identities.
Before installing, be comfortable giving the skill access to the transcript and the chosen entity folder, because it will read those files and append local meeting history. Review the generated note and recap email before using them; the skill says it drafts email only and should not send anything automatically.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
