Note: The attack in this article can also be conducted without a Skill, via indirect prompt injection (e.g., a hidden instruction Zoom ingests, such as an email).
Skills are typically distributed through online marketplaces and can be shared between users within Zoom; prior research shows that attackers are uploading malicious Skills to these online registries.
Note: Zoom does offer users a warning when uploading a Skill, but we do not believe it adequately informs them of the risks. The warning: “This skill is not from Zoom's official catalog and hasn't been verified by Zoom. Make sure you trust this skill's creator before installing.”