Back to skill

Security audit

笔记

Security checks across malware telemetry and agentic risk

Overview

This meeting-note skill is mostly a text workflow, but it asks for broad command, file, and API-related authority that is not clearly scoped to note generation.

Review this skill before installing if your agent has shell, file-write, or network/API access. It appears to be a meeting-note template with no executable payload, but its declared tools and generic API/command instructions are broader than the core task requires.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill declares `exec` capability even though its stated purpose is meeting-note generation and structuring. Unnecessary command execution expands the attack surface: if an agent follows the skill mechanically, user-provided meeting content or follow-up prompts could be routed into shell execution paths that are not needed for the business function.

Context-Inappropriate Capability

Medium
Confidence
85% confidence
Finding
The skill description advertises API integration, webhook configuration, and system-connection use cases that are broader than simple meeting-note summarization. This capability creep can cause an agent to request or use networked/system actions in response to ordinary note-taking tasks, increasing the chance of data exfiltration, unsafe outbound requests, or misuse of credentials.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The activation guidance is broad and mixes meeting-note tasks with API integration and system connection scenarios, which weakens trigger boundaries. Over-broad invocation criteria make it easier for an agent to apply this skill in contexts where higher-risk tools are available, potentially causing unintended execution or external actions from prompts that should have stayed purely textual.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.