Back to skill

Security audit

AI会议助手免费版

Security checks across malware telemetry and agentic risk

Overview

This meeting assistant is mostly coherent, but it can join live meetings, capture and save private conversation content, and store credentials without enough privacy, retention, or consent guidance.

Review before installing. Use this only for meetings where you have authority to add a bot and where participant notice or consent requirements are satisfied. Avoid using it for sensitive calls unless you understand where transcripts, summaries, API keys, and callback data are stored or sent, and keep generated files out of shared folders and source control.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger condition is phrased so broadly ('需要AI模型调用、智能对话、Agent编排、LLM应用时使用') that the skill could be invoked for many unrelated requests, causing the agent to apply meeting-join behavior outside the user's actual intent. In this skill's context, that is especially risky because it can lead to joining live meetings, capturing audio, and generating transcripts or notes from privacy-sensitive conversations without sufficiently explicit scoping.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill describes real-time listening and transcription of meetings but does not prominently warn users about consent, privacy, retention, and potential legal/compliance obligations. Because the tool is designed to enter third-party meetings and persist their contents, missing warnings materially increase the chance of unauthorized recording or disclosure of sensitive business or personal information.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The examples show automatic meeting summary generation and writing configuration files containing API credentials, but they do not clearly warn that sensitive meeting content and secrets may be written to disk. This can expose private discussions or credentials to other local users, backups, logs, or source-control mistakes, especially on shared or poorly secured systems.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.