Back to skill

Security audit

智能会议机器人

Security checks across malware telemetry and agentic risk

Overview

This meeting-bot skill is not clearly malicious, but it asks for broad authority and describes autonomous meeting attendance, listening, transcription, and speaking without enough consent and scope controls.

Review before installing. Only use this skill in environments where meeting bots, transcription, recording, and automated participation are allowed, and require explicit user confirmation before joining or listening. Confirm where transcripts and API credentials are stored, disable broad exec/write access if possible, and avoid using it for the generic automation scenarios listed in the artifact.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest and description present the skill as a meeting bot, but also advertise unrelated project management, workflow automation, content generation, file handling, and environment-management uses. This scope drift can cause an agent to invoke a high-privilege skill in contexts far beyond meeting participation, increasing the chance of unnecessary file access, command execution, or data handling under misleading pretenses.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill declares read, write, and exec capabilities even though the documented purpose is joining meetings, transcription, and TTS handling. Granting general command execution without a tightly justified need expands the attack surface and allows prompt-routed misuse if an agent trusts the manifest too broadly.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The documented use cases include generic team collaboration, API integration, content generation, file batch processing, environment management, and data processing, none of which are constrained to meeting operations. This broadens the apparent authority of the skill and may cause agents or users to apply a meeting bot to high-risk general automation tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The invocation guidance is overly broad and internally conflicting, claiming meeting-bot behavior while recommending use for project management, planning, tracking, and collaboration generally. Ambiguous routing criteria can cause autonomous systems to select this privileged skill for tasks outside its intended scope, leading to overreach and unsafe tool use.

Vague Triggers

High
Confidence
98% confidence
Finding
The statement that the bot will proactively detect and join meetings 'without manual trigger' describes autonomous activation without clear authorization, source constraints, or approval requirements. In a meeting context, this is especially risky because it can result in unauthorized attendance, recording, or transcription of sensitive conversations.

Missing User Warnings

High
Confidence
99% confidence
Finding
The skill describes real-time transcription, timestamping, speaker attribution, summaries, and action-item extraction, but does not provide a clear warning about recording consent, privacy implications, retention, or where transcripts are stored. In a meeting assistant, omission of these disclosures is dangerous because users may unknowingly capture sensitive or regulated communications.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The documentation promotes autonomous meeting participation but does not clearly warn users that the bot may enter meetings, listen, and interact on their behalf. This is dangerous because participants may not expect an automated agent to join or speak, creating privacy, consent, and policy-compliance risks.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.