Aegean Calendar
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's high-level description and claimed provider support do not match the concrete instructions and metadata: it omits any authentication or runtime details for calendar providers and has inconsistent metadata, so it's unclear how it will access or sync calendars.
This skill looks incomplete or inconsistent rather than clearly malicious, but you should not install it without more information. Ask the publisher for concrete runtime details: how will it authenticate to Google/Apple/Outlook (OAuth flow, scopes, token storage)? Where are API calls sent and is any data forwarded to third-party endpoints? Verify the skill's source and resolve the metadata mismatches (owner, slug, version). Prefer skills that declare required env vars or an explicit OAuth flow and have a verifiable homepage or source repository. If you proceed, do not provide credentials directly into free-text prompts — use the platform's secure connector or OAuth flow, and monitor for unexpected credential requests.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
No VirusTotal findings for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
