zoom-meeting-sdk-electron

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely composed of Markdown documentation files, including lifecycle workflows, architecture patterns, and setup guides. No executable scripts, binaries, or automated tools are present within the skill files.
  • [DATA_EXFILTRATION]: The skill adheres to security best practices by explicitly instructing developers to keep SDK secrets server-side and to generate short-lived JWT tokens on a backend service rather than embedding credentials in the Electron bundle.
  • [INDIRECT_PROMPT_INJECTION]: The documentation describes the handling of meeting-related data (e.g., chat messages, meeting IDs, and participant information) which constitutes a standard data ingestion surface. The guidelines include recommendations for validating IPC boundaries and data flows to mitigate risks associated with untrusted content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 09:55 PM
Security Audit — agent-trust-hub — zoom-meeting-sdk-electron