Security audit
gws-calendar-agenda
Security checks for vulnerabilities and agentic risk
Overview
This skill is a read-only helper for viewing Google Calendar agenda data through the disclosed gws command-line tool.
Install only if you intend to let the `gws` CLI read Google Calendar agenda data. Review the referenced shared gws skill and your Google account permissions, especially because the default view queries all calendars unless filtered.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
