Back to skill

Security audit

会议纪要基础版

Security checks across malware telemetry and agentic risk

Overview

This meeting-note skill is not clearly malicious, but it asks for broad local command/file authority while giving inconsistent privacy and network-use guidance.

Review before installing. Use this only if you are comfortable with a meeting-note skill that can guide an agent to read local files, execute commands, inspect secret-related environment-variable names, and potentially use external APIs or callback URLs. Do not provide confidential meeting transcripts unless you first constrain network use and confirm where outputs, cache, and API credentials are stored.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The skill claims FREE-version data is stored locally and not uploaded to the cloud, yet other sections permit external API use and asynchronous callback URLs. This creates a deceptive trust boundary: users may provide sensitive meeting content believing it remains local when the workflow can transmit it off-host, leading to confidentiality and compliance risks.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The skill is presented as a narrow personal meeting-note tool, but its documented behavior includes generic API invocation and asynchronous callback handling that exceed that stated scope. That mismatch can cause users or agents to authorize broader data access and outbound communication than expected, increasing the chance of unintended exfiltration or misuse.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The environment/API-key inspection guidance and callback capability are not well justified for a meeting-note skill and can expose sensitive operational details. Even though the example masks values, it encourages enumeration of secrets-related environment variables and normalizes network-capable behavior that could be repurposed by an agent or user into credential discovery or data exfiltration workflows.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The invocation model relies on broad natural-language triggering without a narrowly scoped command format. In agent environments this can cause accidental activation during ordinary conversation, potentially leading to unintended file access, command execution, or external calls under the skill's permissions.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The example trigger phrase is a normal conversational sentence, making collisions with ordinary user requests likely. In an exec-enabled skill, accidental triggering can expand a harmless request into automated tool use or outbound processing without the user's informed intent.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill metadata advertises read/exec/glob/grep capabilities but the description does not clearly warn that commands may be executed or that external APIs may be contacted. This omission weakens informed consent and increases the chance that users expose local data or approve a skill whose operational risk is materially higher than its benign meeting-note framing suggests.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.