zoom-meeting-sdk-electron
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely composed of Markdown documentation files, including lifecycle workflows, architecture patterns, and setup guides. No executable scripts, binaries, or automated tools are present within the skill files.
- [DATA_EXFILTRATION]: The skill adheres to security best practices by explicitly instructing developers to keep SDK secrets server-side and to generate short-lived JWT tokens on a backend service rather than embedding credentials in the Electron bundle.
- [INDIRECT_PROMPT_INJECTION]: The documentation describes the handling of meeting-related data (e.g., chat messages, meeting IDs, and participant information) which constitutes a standard data ingestion surface. The guidelines include recommendations for validating IPC boundaries and data flows to mitigate risks associated with untrusted content.
Audit Metadata