Back to skill

Security audit

Zoom Unofficial Community Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Zoom admin CLI, but it uses broad account privileges and handles Zoom access tokens in unsafe ways that users should review before installing.

Install only if you are comfortable giving this skill Zoom account-level API access. Create a dedicated Zoom app, grant only the scopes needed for the commands you will use, avoid using system-wide pip installation, and treat the local `.env` file and `/tmp/zoom_token.json` as sensitive credentials. Review destructive and posting commands before allowing an agent to run them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/zoom.py:28
Finding

OAuth Bearer Token Stored in an Unsafe Predictable Temporary File

Content
View full analysis
time.time() + 60: return cached["access_token"] except (json.JSONDecodeError, KeyError): pass ``` ```python with open(TOKEN_CACHE, "w") as f: json.dump(data, f) ``` ### Technical Analysis The application stores a reusable Zoom OAuth access token in the fixed, globally predictable path `/tmp/zoom_token.json`. The file is opened using ordinary Python file operations without: - Explicitly setting permissions to `0600` - Atomically creating the file with exclusive access - Verifying that the path is a regular file - Verifying file ownership - Rejecting symbolic links - Using a private per-user runtime directory The actual permissions therefore depend on the process umask. In a multi-user environment, another local user may be able to read the cached token. The separate existence check followed by `open()` also introduces a time-of-check/time-of-use condition. Because the destination is predictable, a local attacker may pre-create `/tmp/zoom_token.json` as a symbolic link. When the victim runs the CLI and a new token is obtained, the application follows that link and writes JSON token data to the linked destination, provided the victim has permission to write there. The cached response may contain fields beyond the access token, since the complete OAuth response is written to disk after adding `expires_at`. ### Attack Path 1. An attacker with local access predicts the fixed cache path `/tmp/zoom_token.json`. 2. The attacker either monitors or reads a cache created with permissive effective permissio ...[truncated 1185 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/zoom.py:312
Finding

Zoom Bearer Token Appended to Unvalidated Recording Download URLs

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:13
Finding

Unpinned Dependencies Installed into System Python with Protection Bypass

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (55)

Tainted flow: 'account_id' from os.environ.get (line 54, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/zoom.py (reported line 73)May include surrounding context.

python
pass

    # Request new token
    resp = requests.post(
        TOKEN_URL,
        params={"grant_type": "account_credentials", "account_id": account_id},
        auth=(client_id, client_secret),

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented purpose does not accurately match the behaviors described, including undeclared access to phone logs, RTMS live-meeting control, and AI meeting summaries, while also overstating support for calendar and general OAuth apps. This kind of mismatch is dangerous because reviewers and users may grant trust or permissions based on incomplete or inaccurate understanding of what the skill can actually do.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
Use `scripts/zoom.py` to interact with Zoom's REST API.

Static analysis

No suspicious patterns detected.