Back to skill

Security audit

Zoom Meeting Assistance Rtms Unofficial Community

Security checks for vulnerabilities and agentic risk

Overview

This is a real Zoom meeting recording skill, but it needs Review because it captures sensitive meeting data and has verified unauthenticated webhook, TLS, and command-injection risks.

Review carefully before installing. Use only in a controlled environment after adding Zoom webhook signature verification, authenticated admin endpoints, strict allowlists for RTMS URLs, normal TLS verification, safe ffmpeg invocation without a shell, filename/path validation, retention/deletion controls, and clear participant consent and data-handling rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
index.js:73
Finding

Unauthenticated webhook enables arbitrary outbound WebSocket connections

Content
View full analysis
{ // Respond with HTTP 200 status res.sendStatus(200); console.log('RTMS Webhook received:', JSON.stringify(req.body, null, 2)); const { event, payload } = req.body; // Handle URL validation event if (event === 'endpoint.url_validation' && payload?.plainToken) { const hash = crypto .createHmac('sha256', ZOOM_SECRET_TOKEN) .update(payload.plainToken) .digest('hex'); console.log('Responding to URL validation challenge'); return res.json({ plainToken: payload.plainToken, encryptedToken: hash, }); } // Handle RTMS started event if (event === 'meeting.rtms_started') { console.log('RTMS Started event received'); const { meeting_uuid, rtms_stream_id, server_urls, operator_id } = payload; const metadataDir = getRecordingsPath(rtms_stream_id); fs.mkdirSync(metadataDir, { recursive: true }); const metadata = { meeting_uuid, rtms_stream_id, operator_id, server_urls, start_time: new Date().toISOString(), event_ts: req.body.event_ts }; fs.writeFileSync( path.join(metadataDir, 'metadata.json'), JSON.stringify(metadata, null, 2) ); connectToSignalingWebSocket( meeting_uuid, rtms_stream_id, server_urls ); } }); ``` ```js function connectToSignalingWebSocket(meetingUuid, streamId, serverUrl) { console.log(`Connecting to signaling WebSocket for stream ${streamId}`); console.log('Stream ID:', streamId); console.log('Server URL:', serverUrl); const safeStreamId = sanitizeFileName(streamId); console.log('Sanitized Meeting UUID:', safeStreamId); const ws = new WebSocket(serverUrl); cons ...[truncated 2828 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
index.js:607
Finding

TLS certificate verification is disabled for sensitive media WebSocket connections

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
saveRawAudioAdvance.js:8
Finding

Untrusted audio user IDs enable path traversal and FFmpeg shell command injection

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
chatWithClawdbot.js:46
Finding

Meeting transcripts are passed directly to a tool-capable local agent without a robust untrusted-data boundary

Content
View full analysis
{ const args = [ 'agent', '--local', '--json', '--session-id', 'rtms-meeting-assistant', '--message', message ]; execFile( OPENCLAW_BIN, args, { timeout, maxBuffer: 10 * 1024 * 1024 }, (err, stdout, stderr) => { if (err) { console.error( '❌ OpenClaw error:', err.message ); if (stderr) { console.error('stderr:', stderr); } return reject(err); } try { const result = JSON.parse(stdout); if ( result.payloads && Array.isArray(result.payloads) ) { const text = result.payloads .map(p => p.text) .filter(Boolean) .join('\n'); resolve(text || stdout.trim()); } else { resolve( result.reply || result.message || result.content || stdout.trim() ); } } catch { resolve(stdout.trim()); } } ); }); } ``` ```js export async function generateDialogSuggestions( transcript ) { try { const dialogPromptTemplate = readFileSync( join( __dirname, 'query_prompt_dialog_suggestions.md' ), 'utf-8' ); const filledPrompt = dialogPromptTemplate.replace( /\{\{meeting_transcript\}\}/g, transcript ); console.log( '🗣️ Generating dialog suggestions via OpenClaw...' ); ...[truncated 4338 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (38)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README advertises full meeting capture of audio, video, transcripts, screenshare, chat, and onward AI/WhatsApp processing, but it does not prominently warn about participant consent, legal notice requirements, retention, or handling of sensitive data. In the context of a meeting-recording skill, this omission is dangerous because operators may deploy it to capture highly sensitive communications and transmit derived content externally without informing participants or implementing privacy controls.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a full Zoom RTMS meeting ingestion and analysis assistant, including webhook handling, capture of multiple meeting modalities, AI analysis, and notifications. The provided code chunk only performs post-processing of existing local media files by converting raw PCM audio to WAV and H264 video to MP4 in a recordings directory. This is a materially narrower and different behavior than the declared purpose. While media conversion could be a supporting implementation detail in a larger RTMS pipeline, this code chunk by itself does not implement the core declared capabilities and instead exposes an undeclared primary function: local transcoding.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a full Zoom RTMS meeting assistant with webhook handling, multimodal meeting capture, AI analysis, and WhatsApp notifications. The supplied code chunk does something much narrower: it saves incoming raw audio chunks to local files and manages file write streams. While raw audio storage could be a supporting component of a meeting capture system, the code does not implement most of the described functionality. It also accesses the local filesystem, which is a concrete resource usage not reflected in the declared permissions. Therefore the description does not accurately represent what this specific code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The supplied code chunk implements a narrow media-storage utility: it saves raw H.264 video frames for a stream, ensures SPS/PPS headers are written, and inserts black frames when timestamp gaps are detected. While this is loosely related to the declared meeting-media capture domain, it does not implement the described assistant behavior such as webhook handling, multimodal capture, transcription/chat/screenshare handling, AI analysis, or notifications. The description substantially overstates what this code actually does, so this chunk is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description claims a broad RTMS meeting assistant covering multiple media types, webhook event handling, AI analysis, and WhatsApp notifications. This code chunk does not implement those functions. Instead, it narrowly handles JPEG screenshare frames, compares them for uniqueness, stores selected frames, and compiles them into a PDF plus a frame timestamp text file. That is a materially narrower and different behavior than the declared end-to-end meeting assistant. While screenshare capture is one subset of the declared scope, the missing claimed capabilities and the code’s specific document-generation behavior make the description inaccurate for this chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code chunk is a narrow transcript-file writer, not a full Zoom RTMS meeting assistant. It sanitizes a stream ID, tracks stream start timestamps, creates a recordings directory, and appends transcript content to VTT, SRT, and TXT files. While transcript handling is loosely related to the declared meeting-analysis domain, the declared description emphasizes webhook-driven RTMS capture of multiple media types plus AI analysis and notifications. None of those core behaviors appear in this code. Additionally, the code performs local filesystem writes to persist transcripts, which is a concrete capability absent from the declared description. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is explicitly designed to capture and retain highly sensitive meeting content including audio, video, transcript, screenshare, chat, participant events, summaries, and sentiment outputs, yet it does not present a prominent warning or consent/privacy notice. In this context, the omission is dangerous because users may expose confidential business, legal, or personal communications without understanding the breadth of collection, storage duration, and downstream analysis/notification behavior.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 146)May include surrounding context.

md
// Import OpenClaw AI functions
import { chatWithClawdbot, chatWithClawdbotFast, generateDialogSuggestions, analyzeSentiment, generateRealTimeSummary, queryCurrentMeeting, notifyUser } from './chatWithClawdbot.js';

// Load environment variables from a .env file
dotenv.config();

// Runtime notification toggle

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · index.js (reported line 29)May include surrounding context.

js
// Import OpenClaw AI functions
import { chatWithClawdbot, chatWithClawdbotFast, generateDialogSuggestions, analyzeSentiment, generateRealTimeSummary, queryCurrentMeeting, notifyUser } from './chatWithClawdbot.js';

// Load environment variables from a .env file
dotenv.config();

// Runtime notification toggle

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The webhook handler calls res.sendStatus(200) before checking for Zoom's endpoint.url_validation event, then attempts to send a JSON challenge response afterward. In Express this means the response is already committed, so URL validation can fail and the endpoint may accept unauthenticated requests without performing the expected handshake semantics. In a meeting-capture skill, broken webhook validation is especially risky because webhook events trigger recording, storage, WebSocket connections, and downstream AI processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

On meeting.rtms_started, the skill immediately creates storage directories and writes meeting metadata, and elsewhere it persists raw audio, video, screen-share images, transcripts, chat, and summaries to local disk without any visible warning, retention control, or permission gating in this file. Persisting comprehensive meeting artifacts materially raises confidentiality and compliance risk if the host is compromised, the filesystem is shared, or retention is longer than intended. In a meeting-recording assistant, this is especially dangerous because the captured data set is broad and highly sensitive.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code reads transcript and event data from disk and forwards transcript content to external AI-analysis functions such as generateDialogSuggestions, analyzeSentiment, generateRealTimeSummary, and notifyUser, with no visible consent, disclosure, minimization, or access control checks in this file. This creates a privacy and data-handling risk because sensitive meeting content may be transmitted to third-party services and pushed through notifications. Given the skill’s purpose is live meeting capture, the context increases severity because the data is likely confidential business or personal communication.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: path-to-regexp==0.1.12 — 1 advisory(ies): CVE-2024-45296 (path-to-regexp vulnerable to Regular Expression Denial of Service via multiple r)

High
Category
Supply Chain
Confidence
95% confidence
Finding

path-to-regexp 0.1.12 is used by Express routing and the cited ReDoS issue can allow crafted request paths to consume excessive CPU during route matching. Because this skill is an internet-facing webhook receiver for Zoom RTMS events, an attacker may be able to hit exposed endpoints repeatedly and degrade or deny service.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: sharp==0.34.4 — 2 advisory(ies): GHSA-f88m-g3jw-g9cj (sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-); GHSA-rgj7-g3m4-5g8c (sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545)

High
Category
Supply Chain
Confidence
89% confidence
Finding

sharp 0.34.4 pulls in vulnerable native image-processing components, and image/media parsers are a common target for memory corruption or denial-of-service attacks. This skill processes meeting artifacts such as video frames and screenshares, which makes media-handling bugs more relevant than in a typical app because attacker-controlled meeting content could reach the vulnerable library.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.18.2 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
93% confidence
Finding

ws 8.18.2 is flagged for both memory disclosure and memory exhaustion issues, which are especially serious in a real-time streaming integration. Because this skill captures Zoom RTMS media streams over WebSocket-style channels, a remotely triggered flaw in the WebSocket stack could expose process memory or exhaust resources, disrupting live meeting capture and potentially leaking sensitive meeting data.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: sharp==0.34.4 — 2 advisory(ies): GHSA-f88m-g3jw-g9cj (sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-); GHSA-rgj7-g3m4-5g8c (sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545)

High
Category
Supply Chain
Confidence
98% confidence
Finding

The project includes sharp 0.34.4, which is flagged as affected by multiple upstream image-processing library vulnerabilities. In a meeting assistant that may ingest screenshots, frames, or other user-controlled media from Zoom RTMS, vulnerable image parsing can increase the risk of denial of service, crashes, or potentially more serious native-library exploitation depending on the exact affected code paths.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.18.2 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
97% confidence
Finding

The project depends on ws with advisories for uninitialized memory disclosure and memory-exhaustion denial of service. Because this skill is explicitly designed around real-time media streams and webhook-triggered meeting processing, WebSocket reliability and safe frame handling are security-relevant; a vulnerable ws version could let attackers crash the service or potentially expose sensitive meeting-related data in memory.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 115)May include surrounding context.

bash
# Toggle WhatsApp notifications on/off
curl -X POST http://localhost:3000/api/notify-toggle \
  -H "Content-Type: application/json" -d '{"enabled": false}'

# Check notification status

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents network access, environment-variable secrets, webhook handling, and local data retention, but it does not declare any explicit tool scope or permissions boundary. That makes the operational capabilities opaque to users and reviewers and increases the chance of over-privileged execution or accidental misuse of sensitive credentials and network functions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

bash
# Toggle WhatsApp notifications on/off
curl -X POST http://localhost:3000/api/notify-toggle -H "Content-Type: application/json" -d '{"enabled": false}'

# Check notification status
curl http://localhost:3000/api/notify-toggle

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code invokes a local external CLI agent through child_process and feeds it meeting transcripts, queries, and metadata. Even though execFile avoids shell injection, the capability is broader than the stated Zoom RTMS assistance purpose and creates a powerful execution boundary where sensitive meeting data is handed to an opaque local agent that may access tools, files, or networks outside the skill's intended scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends meeting transcripts, user questions, and related context to an external/local OpenClaw agent without any visible consent gate or user-facing disclosure. In a meeting assistant context, this is especially sensitive because transcripts may contain confidential business, personal, or regulated information, and forwarding them to another processing component expands exposure and compliance risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The /api/notify-toggle endpoints allow any caller to read and modify a global runtime setting without authentication or authorization. An attacker could disable notifications to hide meeting activity or enable noisy outbound alerts, affecting operational visibility and user trust. In this context, notification state directly influences awareness around sensitive meeting capture and AI summaries, so even a small control surface becomes meaningful.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This prompt is designed to process the full meeting transcript for every participant and infer per-user emotional state, which is privacy-sensitive behavioral profiling. In the context of a Zoom RTMS assistant that captures audio, transcript, screenshare, and chat, performing sentiment analysis on all participants without an explicit user-facing notice, consent flow, or minimization controls creates meaningful privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The function creates or reuses a write stream and writes audio chunks to a .raw file, which is a safety-relevant file write involving potentially sensitive user data. In this file there is no confirmation prompt, logging, docstring, or comment warning that user audio is being persisted to disk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.insecure_tls_verification

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
chatWithClawdbot.js:28

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
index.js:610