Back to skill

Security audit

Meeting Coordinator - In Person + Virtual (Google Meet)

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed scheduling assistant that uses sensitive calendar, email, and venue tools in ways that match its purpose.

Install only if you are comfortable giving the agent Gmail/Calendar access through a dedicated low-privilege account. Share only the intended calendar, keep the human approval gates in place, and be aware that availability checks may reveal event titles, times, and IDs to the agent and local logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The script retrieves calendar events and then emits event summaries, start/end times, and IDs in JSON without any consent prompt, minimization, or redaction. In a meeting-coordinator skill, this is sensitive scheduling metadata and can expose private calendar contents to downstream logs, agents, or users beyond what is necessary to report availability.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal