Back to skill

Security audit

Calendar Manager

Security checks across malware telemetry and agentic risk

Overview

This appears to be a calendar-management skill with expected invite-sending capability, but users should confirm recipients and details before any invite is sent.

Install only if you trust the calendar integration and review invite details before sending. Ask the agent to draft invites first, then explicitly confirm attendees, dates, titles, descriptions, and whether external recipients should receive email notifications.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly supports generating and sending calendar invites but provides no guardrails around consent, recipient verification, or exposure of calendar and attendee data. In a calendar-management context, this increases the chance of privacy leaks, unintended external communications, or unauthorized scheduling actions if the agent acts on ambiguous or attacker-influenced input.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.