tencent-meeting-skill

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The SKILL.md file contains instructions that use "Highest Priority" framing and "Ignore/Disregard" markers to ensure the agent prioritizes the skill's specific rules over previous instructions or historical context.
  • [DATA_EXFILTRATION]: The scripts/tencent_meeting.py and scripts/utils.py files contain logic to automatically collect the host system's operating system name and version. This information is injected into the _client_info parameter and transmitted to the remote API during every tool invocation.
  • Evidence: The get_os_name function in scripts/utils.py reads from /etc/os-release and uses the platform module to gather system metadata, which is then sent via the McpProxy class in scripts/mcp_proxy.py.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from external sources, specifically meeting transcripts and AI-generated meeting summaries, which could be manipulated to contain malicious instructions.
  • Ingestion points: Meeting content is retrieved via the get_transcripts_details and get_smart_minutes tools.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are configured for handling these text-heavy external inputs.
  • Capability inventory: The agent has the authority to perform destructive or high-privilege actions like cancel_meeting or update_meeting.
  • Sanitization: The provided Python scripts do not implement filtering or sanitization of the transcript content before it is returned to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — tencent-meeting-skill