Back to skill

Security audit

caldav-sync

Security checks for vulnerabilities and agentic risk

Overview

This calendar skill largely does what it says, but it handles reusable calendar credentials and cached private data in ways that need review before installation.

Install only if you trust the CalDAV server and understand it can read, create, modify, and delete remote calendar/task data. Prefer provider presets or HTTPS-only custom endpoints, use app-specific passwords, and review/remove cached data and plaintext credentials under ~/.config/mail-skills if you stop using it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/caldav.js:152
Finding

Basic Authentication Credentials Can Be Sent to Insecure or Untrusted DAV Endpoints

Content
View full analysis
(typeof c === 'string' ? c.toUpperCase() : '') === 'VTODO'); } if (_vtodoSupportCache.has(calendar.url)) { return _vtodoSupportCache.get(calendar.url); } try { const encoded = Buffer.from(`${config.username}:${config.password}`).toString('base64'); const resp = await fetch(calendar.url, { method: 'PROPFIND', headers: { Authorization: `Basic ${encoded}`, ``` ```javascript // scripts/caldav.js:152-158 async function davPut(url ...[truncated 2920 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cache.js:21
Finding

Sensitive Calendar and Task Cache Files Are Written Without Explicit Private Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
setup.sh:173
Finding

Reconfiguration Creates an Insecure Derived Temporary File Containing Account Credentials

Content
View full analysis
"$TEMP_FILE.named" 2>/dev/null || true cat > "$TEMP_FILE" << EOF ``` ### Technical Analysis `mktemp` securely creates `TEMP_FILE`, but `"$TEMP_FILE.named"` is not created by `mktemp`. It is a predictable derivative of the first temporary path and is created by shell redirection under the current umask. The file receives all matching named-account configuration lines, including `USERNAME`, `PASSWORD`, and CalDAV endpoint values. Depending on the umask, it may be locally readable while reconfiguration is in progress. Separately creating a derived filename also weakens the race protections offered by `mktemp`, because another local process may attempt to create or link that path before the redirection occurs. Although the file is removed during ordinary completion, the script has no cleanup trap for interruption or abnormal termination. A failed or interrupted setup can therefore leave the temporary credential copy behind. ### Attack Path 1. A user runs `setup.sh` and selects reconfiguration of the default account. 2. The script creates one secure temporary file using `mktemp`. 3. It constructs the separate path `.named` without securely creating it. 4. Named-account usernames and passwords are copied into that file as plaintext. 5. A local attacker monitors temporary paths, reads a permissively created file, or attempts to race creation of the derived path. 6. If setup is interrupted, the plaintext credential file may remain on disk for later recovery. ### Impact Assessment Successful exploitation may disclose credentials for every named account stored in the shared configuration file, not merely the account being reco ...[truncated 370 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a full CalDAV calendar/task management skill. The supplied code chunk is much narrower: it uses ical.js to parse ICS strings into event/todo/freebusy objects and generate ICS strings for events and todos. While this supports parts of calendar/task data handling and aligns somewhat with event/todo creation representation and free/busy parsing, it does not actually perform CalDAV protocol operations, remote calendar access, querying, synchronization, editing/deleting against a server, or multi-account support. Therefore the description overstates the implemented behavior in this code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 204)May include surrounding context.

md
node scripts/caldav.js --account work list-calendars

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.js (reported line 9)May include surrounding context.

js
const dotenv = require('dotenv');
const { PROVIDERS } = require('./providers');

const SHARED_ENV_PATH = path.join(os.homedir(), '.config', 'mail-skills', '.env');
const FALLBACK_ENV_PATH = path.resolve(__dirname, '../.env');

function findEnvPath() {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/config.js (reported line 10)May include surrounding context.

js
const dotenv = require('dotenv');
const { PROVIDERS } = require('./providers');

const SHARED_ENV_PATH = path.join(os.homedir(), '.config', 'mail-skills', '.env');
const FALLBACK_ENV_PATH = path.resolve(__dirname, '../.env');

function findEnvPath() {

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The script is explicitly designed to write CalDAV credentials into a shared .env file under ~/.config/mail-skills, which constitutes credential materialization in a broadly reusable plaintext location. In the context of a mail/calendar skill ecosystem, a shared config file increases blast radius because any other local tool, skill, backup process, or accidental disclosure involving that file can expose multiple account secrets.

Content

Scanner excerpt · setup.sh (reported line 4)May include surrounding context.

sh
#!/bin/bash

# CalDAV Sync Skill Setup Helper
# Writes to shared config: ~/.config/mail-skills/.env

CONFIG_DIR="$HOME/.config/mail-skills"
CONFIG_FILE="$CONFIG_DIR/.env"

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

This is the same underlying issue manifested in the concrete variable definition of CONFIG_FILE pointing to ~/.config/mail-skills/.env, a shared plaintext credential repository. Because the file is shared across 'mail-skills', compromise or misuse of one component can expose credentials for this and potentially other accounts, making the context more dangerous than a private per-skill store.

Content

Scanner excerpt · setup.sh (reported line 7)May include surrounding context.

sh
# Writes to shared config: ~/.config/mail-skills/.env

CONFIG_DIR="$HOME/.config/mail-skills"
CONFIG_FILE="$CONFIG_DIR/.env"

echo "================================"
echo "  CalDAV Sync Skill Setup"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents use of environment variables, shell execution, and network access but does not declare any explicit tool scope or permission boundaries. In an agent ecosystem, this increases the risk that the skill runs with broader capabilities than users expect, especially since it handles credentials and remote account operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file documents delete-event and delete-todo, which can remove user calendar data, but it does not warn that these operations are destructive or may be irreversible depending on the CalDAV provider. Under the markdown criteria for missing user warnings, data-affecting behaviors should be disclosed clearly.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

md
2. **ctag + etag** — compares calendar tag and resource tags to fetch only changes
3. **full** — fetches all resources (fallback)

Sync state is cached at `~/.config/mail-skills/caldav-cache/` per account and calendar. Write operations (create/update/delete) automatically invalidate the cache.

Use `--force-refresh` to bypass the cache and force a full sync:

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The skill recommends npx skills add ... without a pinned version, which can fetch whatever package version is current at execution time. This creates a supply-chain risk: a compromised or malicious future release could be installed and executed unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.