Back to skill

Security audit

Calendly Quick Book

Security checks for vulnerabilities and agentic risk

Overview

This Calendly booking skill is mostly purpose-aligned, but its always-on broad trigger and unsafe shell-style booking template create avoidable risk around accidental invites, personal data sharing, and command execution.

Review before installing. Use it only if you are comfortable giving OpenClaw a Calendly API token and sending invitee details to Calendly. Prefer narrowing activation to an explicit command, requiring confirmation before booking, and replacing the curl template with safe JSON serialization or an SDK before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:72
Finding

Shell Command Injection Through Unsafely Interpolated Booking Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 72–84
Vulnerability Type: Shell command injection through unsafe user-input interpolation
Risk Level: High

bash
curl -s -X POST "https://api.calendly.com/invitees" \
  -H "Authorization: Bearer $CALENDLY_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "event_type": "{EVENT_TYPE_URI}",
    "start_time": "{TIME_UTC}",
    "invitee": {
      "name": "{NAME}",
      "email": "{EMAIL}",
      "timezone": "{TIMEZONE_IANA}"
    }
  }'

Technical Analysis

The documented workflow places booking values derived from natural-language input directly inside a single-quoted shell argument. No JSON serialization, shell-safe argument construction, or validation requirement is specified for {NAME}, {EMAIL}, or {TIMEZONE_IANA}.

A single quote in one of these fields can terminate the shell string before the intended end of the JSON body. Shell control operators following that quote can then be interpreted as commands rather than booking data. This creates a command-injection risk if an agent implements the documented template through direct placeholder substitution.

Even non-malicious data containing an apostrophe can break the command or produce malformed JSON. JSON escaping alone would not fix the command-injection issue because JSON escaping does not make a value safe for interpolation into shell syntax.

Attack Path

  1. An attacker submits a booking request containing shell syntax in a user-controlled field, such as a crafted attendee name containing a single quote, a command separator, and a shell command.
  2. The skill extracts that text as {NAME} or another booking field.
  3. The agent substitutes the value directly into the documented curl -d '...' command.
  4. The injected single quote closes the shell argument.
  5. The shell interprets the following control operator and command as executable syntax.
  6. The ...[truncated 1179 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not generate request bodies by substituting user-controlled values into shell source code.

  • Prefer a Calendly SDK or an HTTP client library that accepts an in-memory object and serializes it as JSON without invoking a shell.

  • If curl must be used, construct the body with a JSON-aware encoder such as jq and pass each value through a separately quoted argument. For example:

    bash
    payload="$(jq -n \
      --arg event_type "$EVENT_TYPE_URI" \
      --arg start_time "$TIME_UTC" \
      --arg name "$NAME" \
      --arg email "$EMAIL" \
      --arg timezone "$TIMEZONE_IANA" \
      '{
        event_type: $event_type,
        start_time: $start_time,
        invitee: {
          name: $name,
          email: $email,
          timezone: $timezone
        }
      }')"
    
    curl --silent --show-error --fail-with-body \
      -X POST "https://api.calendly.com/invitees" \
      -H "Authorization: Bearer $CALENDLY_API_TOKEN" \
      -H "Content-Type: application/json" \
      --data-binary "$payload"
    
  • Execute commands through an argument-array API rather than through a shell whenever the hosting framework supports it.

  • Validate email addresses, accept only supported IANA timezone identifiers, parse times into a strict ISO 8601 representation, and validate returned Calendly resource URIs before use.

  • Reject control characters and enforce reasonable length limits for attendee names and other text fields as defense in depth.

  • Avoid logging authorization headers, tokens, or complete sensitive booking data.

  • Run the agent with least privilege and restrict its filesystem and outbound-network access to reduce the impact of any command-execution flaw.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 23)May include surrounding context.

2. Get your Calendly API token

  1. Go to Calendly Integrations
  2. Generate a Personal Access Token
  3. Add it to your OpenClaw config:
bash

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description highlights convenience and automatic invites but does not clearly warn that invitee names, email addresses, and scheduling details will be sent to Calendly and may trigger outbound calendar invitations. This creates a privacy and consent risk because users may invoke the skill without realizing third-party data transfer and side effects occur immediately.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 32)May include surrounding context.

3. Configure your default Calendly link

Edit ~/.openclaw/workspace/skills/calendly-quick-book/SKILL.md and update:

markdown
| Default Calendly Link | https://calendly.com/YOUR_USERNAME |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises broad natural-language trigger phrases such as 'book' and 'schedule calendly' without tightly defining activation boundaries. In an agent setting, overly broad triggers can cause unintended invocation from ordinary conversation, leading to accidental booking actions and transmission of personal data to Calendly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is unusually broad because it includes 'any request to book a meeting without sending a link' and metadata.openclaw.always=true, which can cause the skill to activate in contexts the user did not clearly intend. That increases the chance of accidental booking actions or premature collection/transmission of personal data to Calendly without explicit confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill collects invitee name, email, timezone, and scheduling details, then sends them to Calendly, but the description does not clearly warn users that this personal data will be transmitted to a third-party service. This creates a privacy and consent risk, especially because users may provide another person's details expecting only local assistance rather than external processing.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

Step 1: Get Current User

bash
curl -s "https://api.calendly.com/users/me" \
  -H "Authorization: Bearer $CALENDLY_API_TOKEN"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

Step 1: Get Current User

bash
curl -s "https://api.calendly.com/users/me" \
  -H "Authorization: Bearer $CALENDLY_API_TOKEN"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Step 1: Get Current User

bash
curl -s "https://api.calendly.com/users/me" \
  -H "Authorization: Bearer $CALENDLY_API_TOKEN"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

Step 1: Get Current User

bash
curl -s "https://api.calendly.com/users/me" \
  -H "Authorization: Bearer $CALENDLY_API_TOKEN"

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The booking request sends invitee personal data (name, email, timezone, selected time) to Calendly, which is expected for functionality but still presents a real privacy and consent vulnerability when the skill lacks an explicit warning and confirmation flow. Because the skill is designed for fast booking and broad invocation, the context makes accidental third-party transmission more likely and therefore more dangerous.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

Step 4: Create Booking

bash
curl -s -X POST "https://api.calendly.com/invitees" \
  -H "Authorization: Bearer $CALENDLY_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{

Static analysis

No suspicious patterns detected.