AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itprivacy

Knowledge Work Plugins: why it is not safe to use

We found no hidden code or secret leakage, but the skill is built to read sensitive workplace data and retain memory across connected tools.

What we found

Our review did not find hidden instructions, undisclosed destinations, hardcoded secrets, obfuscated content, destructive commands, or privilege escalation in the inspected files. The repository openly describes its components, and the files reviewed were plain markdown and JSON.

The reason this skill did not fully pass is narrower: it is designed to scan sensitive workplace sources such as chat, email, calendar, documents, and knowledge bases, then use that material to build persistent memory and task context across connected services. That behavior is disclosed and aligned with the skill's purpose, and the named connectors are user-chosen services such as Slack, Notion, Asana, Linear, Atlassian, monday.com, ClickUp, and Microsoft 365. Even so, this level of cross-source access can expose more internal context than some users expect at install time.

What to do instead

Use this skill only where users clearly understand which services it will read and what ongoing memory it may retain. Prefer narrower-scoped tools when full workplace scanning is not necessary. Before enabling connectors, confirm data access, retention expectations, and whether non-technical users have been given a clear notice.

Want the same outcome, safely? Use our checked skill instead.

Source: https://github.com/anthropics/knowledge-work-plugins

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.