m365-meeting-note
Warn
Audited by Snyk on Jul 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). SKILL.md Step 1-2 requires fetching an M365 meeting transcript (meetingTranscriptUrl) and reading/parsing its VTT content (which contains all attendees’ spoken text, including outsiders relative to the operating user), then converting it into暫存文字檔/parsed text that is fed into later LLM-based summarization—i.e., runtime outsider-authored free text enters the agent context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata