Back to skill

Security audit

gcal-pro - Google Calendar

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real Google Calendar integration, but its write operations can create, change, or delete calendar events even when confirmation is not actually enforced.

Review carefully before installing. Only use it if you are comfortable granting Google Calendar access, and do not rely on its current confirmation flag to protect against unintended creates, edits, or deletions. Avoid pasting or displaying OAuth credential files in chats or logs, and consider testing with a non-critical calendar first.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gcal_core.py:337
Finding

Calendar Mutations Execute Without Enforced User Confirmation

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/gcal_license.py:32
Finding

Any Well-Formed License Key Grants Pro Write Access

Content
View full analysis
bool: """ Validate a license key format. Real implementation would verify against Gumroad API or similar. For MVP, we use a simple checksum validation. """ if not key: return False # Expected format: GCAL-XXXX-XXXX-XXXX parts = key.upper().strip().split("-") if len(parts) != 4 or parts[0] != "GCAL": return False # Simple checksum: last 4 chars should be based on first 3 parts check_input = "-".join(parts[:3]) expected_check = hashlib.md5(check_input.encode()).hexdigest()[:4].upper() # For now, accept any well-formed key (implement real validation later) # In production: verify against Gumroad API return all(len(p) == 4 for p in parts[1:]) ``` The accepted key is then converted directly into a trusted local authorization record: ```python # Create license file license_data = { "key": key.upper().strip(), "tier": "pro", "valid": True, "activated_at": datetime.utcnow().isoformat(), "machine_id": get_machine_id() } try: with open(LICENSE_FILE, "w") as f: json.dump(license_data, f, indent=2) ``` ### Technical Analysis The function computes `expected_check` but never compares it with the supplied key. Instead, it accepts any value with the prefix `GCAL` and three four-character components. After this format-only check succeeds, `activate_license()` writes `"tier": "pro"` and `"valid": true` to a locally controlled JSON file. `is_pro()` subsequently trusts these fields, and `gcal_auth.py` uses the result when choosing OAuth scopes. Therefore, the license check is an ineffective access-control boundary rather than a genuine validation mechanism. The local file is als ...[truncated 1312 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
docs/GOOGLE_CLOUD_SETUP.md:127
Finding

Credential Verification Commands May Print the Complete OAuth Client Secret

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unbounded and Unhashed Dependency Installation Is Not Reproducible

Content
View full analysis
=2.23.0 google-auth-oauthlib>=1.1.0 google-auth-httplib2>=0.1.1 google-api-python-client>=2.100.0 pytz>=2023.3 python-dateutil>=2.8.2 ``` The installation documentation executes these unconstrained requirements directly: ```text pip install -r requirements.txt ``` ### Technical Analysis Every dependency uses a lower bound without an upper bound, exact version, or integrity hash. Two installations at different times may consequently resolve to different package versions. Future releases are accepted automatically even if they introduce incompatible behavior or are compromised upstream. The reviewed package names are consistent with the declared Google Calendar functionality, and no typosquatted or clearly malicious dependency was identified. The risk arises from non-reproducible resolution and absence of artifact integrity verification rather than from evidence that the currently named packages are malicious. Because Python packages can execute code during installation and are imported into a process handling OAuth tokens and calendar data, compromise of a resolved dependency could have significant consequences. ### Attack Path 1. A future release of an allowed dependency or transitive dependency is compromised, malicious, or unexpectedly incompatible. 2. A user runs `pip install -r requirements.txt`. 3. The resolver selects the new release because it satisfies the unbounded `>=` constraint. 4. Package installation or later import executes the affected code. 5. Code runs with the installing user’s privileges and may access files or credentials available to that process, including the Skill’s OAuth configuration. ### Impact Assessment A compromised dependency could execute with the local user’s privileges and potentially read ...[truncated 381 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (58)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 114)May include surrounding context.

md
| File | Purpose |
|------|---------|
| `client_secret.json` | OAuth app credentials (you provide) |
| `token.json` | Your access token (auto-generated) |
| `license.json` | Pro license (if purchased) |

## Clawdbot Integration

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented purpose is calendar management, but the detected behavior includes license activation/deactivation, machine fingerprinting, and local license-state handling that are not clearly disclosed in the main description. This mismatch can hide sensitive side effects from users and reviewers, weakening informed consent and making it harder to assess what local data the skill manipulates.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The file locations section explicitly documents storage of OAuth client credentials, access tokens, and license data in a predictable path under the user's home directory. In a skill that also appears to use file and shell capabilities, predictable local secret storage increases the risk of unauthorized access, leakage, or misuse by other components or compromised prompts.

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

text
~/.config/gcal-pro/
├── client_secret.json   # OAuth app credentials (user provides)
├── token.json           # User's access token (auto-generated)
└── license.json         # Pro license (if purchased)

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The documented presence of an auto-generated access token on disk means long-lived authentication material may be locally persisted in a predictable location. If the agent environment, shell access, or another tool can read that file, an attacker could gain calendar access and act as the user against Google APIs.

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

text
~/.config/gcal-pro/
├── client_secret.json   # OAuth app credentials (user provides)
├── token.json           # User's access token (auto-generated)
└── license.json         # Pro license (if purchased)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README-INSTALL.txt (reported line 32)May include surrounding context.

text
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 40)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 113)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 131)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 4)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 123)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 137)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 140)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 149)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 152)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 162)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 168)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 177)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 207)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gcal_auth.py (reported line 20)May include surrounding context.

python
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gcal_auth.py (reported line 39)May include surrounding context.

python
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gcal_auth.py (reported line 78)May include surrounding context.

python
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 178)May include surrounding context.

⚠️ NEVER commit these files to git:

  • client_secret.json — Your app's credentials
  • token.json — User's access tokens

Add to .gitignore:

text

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The suggested .gitignore entry *.json is overly broad and can cause developers to ignore all JSON files in the repository, potentially hiding security-relevant configuration, policy, or manifest changes from version control and code review. While not direct credential theft, this weakens auditability and can lead to accidental omission of important non-secret files.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 182)May include surrounding context.

Add to .gitignore:

text
client_secret.json
token.json
*.json

Static analysis

No suspicious patterns detected.