zoom-automation
Warn
Audited by Gen Agent Trust Hub on Mar 5, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires adding
https://rube.app/mcpas an external MCP server. This establishes a dependency on a third-party domain for fetching tool schemas and execution logic, which is not part of the predefined trusted vendors list. - [COMMAND_EXECUTION]: The skill exposes powerful administrative tools for Zoom, including
ZOOM_CREATE_A_MEETING,ZOOM_DELETE_MEETING_RECORDINGS, andZOOM_UPDATE_A_MEETING. These capabilities allow for the creation, modification, and permanent deletion of organizational resources. - [DATA_EXFILTRATION]: The skill provides tools to access sensitive information, such as
ZOOM_GET_PAST_MEETING_PARTICIPANTS,ZOOM_GET_A_MEETING_SUMMARY(AI-generated content), andZOOM_LIST_ALL_RECORDINGS. It also specifically requestsdownload_access_tokento retrieve JWTs for downloading recordings, which involves the movement of sensitive access credentials to the agent context.
Audit Metadata