tencent-meeting-skill
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The
SKILL.mdfile contains instructions that use "Highest Priority" framing and "Ignore/Disregard" markers to ensure the agent prioritizes the skill's specific rules over previous instructions or historical context. - [DATA_EXFILTRATION]: The
scripts/tencent_meeting.pyandscripts/utils.pyfiles contain logic to automatically collect the host system's operating system name and version. This information is injected into the_client_infoparameter and transmitted to the remote API during every tool invocation. - Evidence: The
get_os_namefunction inscripts/utils.pyreads from/etc/os-releaseand uses theplatformmodule to gather system metadata, which is then sent via theMcpProxyclass inscripts/mcp_proxy.py. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from external sources, specifically meeting transcripts and AI-generated meeting summaries, which could be manipulated to contain malicious instructions.
- Ingestion points: Meeting content is retrieved via the
get_transcripts_detailsandget_smart_minutestools. - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are configured for handling these text-heavy external inputs.
- Capability inventory: The agent has the authority to perform destructive or high-privilege actions like
cancel_meetingorupdate_meeting. - Sanitization: The provided Python scripts do not implement filtering or sanitization of the transcript content before it is returned to the agent context.
Audit Metadata