Back to skill

Security audit

meeting-notes

Security checks across malware telemetry and agentic risk

Overview

This is a simple meeting-notes formatting skill with no code, tools, persistence, or hidden data access.

Install this if you want meeting transcripts or rough meeting notes converted into structured minutes. Review the generated minutes for omissions or formatting mismatch, especially if your request was meant as a generic summary rather than formal meeting notes.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
79% confidence
Finding
The skill can be triggered by broad, everyday phrases such as '帮我总结这次会议' or 'meeting summary', which may overlap with normal summarization requests that are not intended to invoke this specific skill. This creates an unintended activation risk that could cause the assistant to apply the meeting-notes workflow in the wrong context, leading to incorrect formatting, omission of user intent, or accidental processing of unrelated content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.