Back to skill

Security audit

会议纪要助手

Security checks for vulnerabilities and agentic risk

Overview

This is a simple local meeting-minutes extractor whose documentation overpromises missing push and todo features, but the inspected files do not show hidden, destructive, persistent, or exfiltration behavior.

Install this only if you want a local Chinese-language helper for turning existing text notes into a simple minutes document. Do not rely on the advertised todo extraction or enterprise chat push commands unless those missing scripts are supplied and reviewed separately. Meeting notes can be sensitive, so keep outputs in an intended workspace path and review content before sharing it elsewhere.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

代码的核心行为与“会议纪要整理”总体方向一致:它读取输入文件、识别讨论/决议/待办相关段落并输出结构化纪要,因此与声明中的会议纪要整理、待办提取部分是相符的。但声明中明确提到支持多渠道推送到企业微信/飞书/钉钉,代码中完全没有任何网络请求、API调用或推送实现;同时也没有录音、转写或实时记录会议的功能,只能处理现成文本。所谓关键讨论点/会议摘要也只是通过简单关键词切换段落收集内容,并非真正的摘要提取。因此该描述相对代码能力存在明显夸大,属于描述与实际行为不完全一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill advertises and demonstrates commands that write output files, but it does not declare any explicit tool scope or permissions boundaries. In an agent setting, undocumented file-write capability can lead to unintended overwrites, creation of sensitive artifacts, or execution beyond what reviewers and users expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Meeting minutes commonly contain confidential business discussions, personnel information, action items, and internal decisions. Advertising pushes to external enterprise channels without any privacy warning, consent checkpoint, or data-sharing explanation increases the risk of accidental disclosure of sensitive information to third-party systems or unintended recipients.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s title, section headers, fallback text, and argument help strings are all hard-coded in Chinese, and the extractor emits Chinese-formatted meeting minutes regardless of user preference. This creates a language/locale policy issue because the skill does not provide any opt-in, configuration, or justification for restricting output to a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The natural-language description and usage guidance are entirely in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.