Back to skill

Security audit

Calendar

Security checks for vulnerabilities and agentic risk

Overview

This is a simple calendar skill that discloses local schedule storage and does not include code, network access, credential handling, or hidden instructions.

Review the broad activation triggers if accidental calendar handling would be disruptive, and remember that events may contain personal information stored locally in /workspace/data/calendar/. No evidence of malicious behavior was found.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
---
AIGC:
    ContentProducer: Minimax Agent AI
    ContentPropagator: Minimax Agent AI
    Label: AIGC
    ProduceID: "00000000000000000000000000000000"
    PropagateID: "00000000000000000000000000000000"
    ReservedCode1: 3044022071b29b3a35bd2beeff306f79bfeffe2e18517b5d7cbda0df4ebe80d8757d87aa02206e6bcac8c8191e0fc74e441701720991b07d6c6eae64426ae0bea53b825e0e78
    ReservedCode2: 304402204397090e3f96286d638117cf444889d113d9bdaa402b72e7e4a92612f9784646022033eeae21a21da47e12e9e594a8c7ee6e28022a1d694852460288ddc624f5d440
description: 日程管理。创建日程、设置提醒、查看安排。
metadata:
    category: 管理
    emoji: "\U0001F4C5"
    triggers:
        - 日程
        - calendar
        - 会议
        - 预约
        - 几点
name: calendar
---

# Calendar 技能

帮你管理日程。

## 功�

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest trigger list contains broad terms such as "会议", "预约", and especially "几点", which commonly appear in ordinary conversation outside the intended skill scope. The file does not provide constraints, exclusion conditions, or negative examples to clarify when these triggers should or should not invoke the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description, trigger phrases, and usage examples are presented primarily in Chinese and imply Chinese-language interaction, with no indication that users may choose another language. This can violate language/locale policy when the skill is expected to support user preference rather than enforce a default language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.