zoom-automation

Warn

Audited by Gen Agent Trust Hub on Mar 5, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires adding https://rube.app/mcp as an external MCP server. This establishes a dependency on a third-party domain for fetching tool schemas and execution logic, which is not part of the predefined trusted vendors list.
  • [COMMAND_EXECUTION]: The skill exposes powerful administrative tools for Zoom, including ZOOM_CREATE_A_MEETING, ZOOM_DELETE_MEETING_RECORDINGS, and ZOOM_UPDATE_A_MEETING. These capabilities allow for the creation, modification, and permanent deletion of organizational resources.
  • [DATA_EXFILTRATION]: The skill provides tools to access sensitive information, such as ZOOM_GET_PAST_MEETING_PARTICIPANTS, ZOOM_GET_A_MEETING_SUMMARY (AI-generated content), and ZOOM_LIST_ALL_RECORDINGS. It also specifically requests download_access_token to retrieve JWTs for downloading recordings, which involves the movement of sensitive access credentials to the agent context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 5, 2026, 07:56 AM