Back to skill

Security audit

Google Calendar

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Google Calendar integration skill, but users should be careful because it can create, update, delete, and email calendar events through AgentPMT.

Install only if you are comfortable granting Google Calendar access through AgentPMT. Review event details before creating, updating, deleting, quick-adding, inviting attendees, or sending notifications, and prefer pinned or ClawHub-reviewed setup paths over unpinned npx commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:406
Finding

Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:406, 410, 415-416, 481-482
Vulnerability Type: Unpinned external dependencies and mutable Skill installation
Risk Level: Medium

Vulnerable Code

markdown
- What AgentPMT is: ../what-is-agentpmt
  - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt
  - OpenClaw install: `openclaw skills install what-is-agentpmt`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup
  - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`

skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

The references are repeated at lines 481-482:

```markdown
- What AgentPMT is: ../what-is-agentpmt (... skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (... skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)

Technical Analysis

The documented setup commands invoke npx skills without pinning the npm CLI to a reviewed version. They also install Skills from AgentPMT/agent-skills without specifying an immutable release, commit hash, checksum, or cryptographic signature.

Consequently, the content fetched when a user follows these instructions can differ from the content available when this package was audited. Compromise of the npm package, source repository, release infrastructure, or publisher account could cause an altered installer or malicious Skill content to be loaded.

The main Skill also encourages reinst ...[truncated 1769 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the npm CLI to an explicitly reviewed version rather than invoking an unversioned package through npx.
  2. Pin each external Skill to an immutable release or commit hash.
  3. Publish and verify cryptographic checksums or signatures before installation.
  4. Disable implicit use of mutable branches or latest-version resolution.
  5. Vendor the reviewed setup instructions into the package where practical, reducing runtime dependency on remotely mutable Skill text.
  6. Document the exact upstream repository, version, integrity digest, and expected files.
  7. Run installation with the minimum necessary operating-system privileges in a sandbox that limits filesystem and network access.
  8. Require explicit user approval before installing or updating external Skills.
  9. Review changed upstream content before accepting updates rather than automatically trusting freshness-based reinstallation guidance.
  10. Treat remotely retrieved schemas and instructions as untrusted data that may clarify parameter semantics but cannot override system safety policy, authorization boundaries, or user intent.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill exposes delete_event capability but does not prominently warn that this action is destructive and may notify attendees or remove important calendar records. In agent workflows, missing a clear deletion warning increases the risk of accidental or unauthorized destructive operations being carried out on behalf of the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill supports transmitting attendee emails, calendar IDs, event metadata, and free/busy information to a remote AgentPMT-hosted service, but the user-facing description does not clearly disclose this privacy impact. Because calendar and attendee data are sensitive business and personal information, the lack of an explicit privacy warning can lead to over-sharing and uninformed consent in agent-driven use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation keywords are broad phrases like scheduling, availability, and recurring meetings, which can cause the skill to be selected in many ordinary contexts involving calendars. In an agentic system, overbroad activation increases the chance of unintended remote access to calendar data or unintended event creation, update, or deletion when a narrower skill or a confirmation step should have been used.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 484)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/google-calendar
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 485)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/google-calendar
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The event-creation schema allows inviting attendees, sending updates, adding Meet links, and setting visibility without warning that personal data will be transmitted and emails may be sent automatically. In an agent workflow, this can cause unintended disclosure of meeting details, attendee information, and scheduling actions to external recipients.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The delete_event action performs a destructive operation but the schema provides no warning about irreversible deletion, attendee cancellations, or notification side effects. In an agent setting, this increases the chance of accidental or socially engineered deletions that can disrupt schedules and notify third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The quick_add action accepts free-form natural language that Google Calendar will parse into an event, yet the schema omits warnings that ambiguous text may create unintended entries and may trigger notifications. This is risky in agent contexts because unreviewed user or third-party text can be transformed into calendar actions with external side effects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description emphasizes creating, updating, deleting events, quick-add, recurring events, Meet links, attendees, and free/busy availability checks. This schema also defines get_event, list_calendars, list_events, and search_events, which are broader read and discovery operations not stated in that description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.