Back to skill

Security audit

iCalendar Sync

Security checks for vulnerabilities and agentic risk

Overview

This calendar skill matches its stated purpose, but needs review because its credential handling can send iCloud credentials to an underdocumented configurable CalDAV URL and debug output may expose sensitive Apple response data.

Install only if you are comfortable giving the skill access to your iCloud calendars and app-specific password. Keep ICALENDAR_SYNC_CALDAV_URL unset unless you have audited the destination, avoid --debug-http with real credentials, prefer keyring storage, and require explicit confirmation before agent-driven update or delete commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
src/icalendar_sync/calendar.py:723
Finding

iCloud credentials can be transmitted to an arbitrary CalDAV endpoint

Content
View full analysis
str: current_url = self.base_url if not self.username or not self.password or requests is None: return current_url max_redirects = 5 timeout = 15 session = requests.Session() auth_header = "Basic " + base64.b64encode( f"{self.username}:{self.password}".encode("utf-8") ).decode("ascii") for _ in range(max_redirects): headers = self._build_request_headers(current_url) headers["Authorization"] = auth_header try: response = session.get( current_url, headers=headers, allow_redirects=False, timeout=timeout, ) self._capture_response_debug(response) except RequestException as exc: if self.debug_http: logger.debug("Endpoint resolution failed: %s", self._format_exception_details(exc)) break if response.status_code in (301, 302, 307, 308): location = response.headers.get("Location") if not location: break next_url = urljoin(current_url, location) next_host = (urlparse(next_url).hostname or "").lower() if next_host and next_host.endswith("icloud.com"): current_url = next_url continue break break return current_url ``` ### Technical Analysis The initial CalDAV URL is read from the `ICALENDAR_SYNC_CALDAV_URL` environment variable without validating its scheme or hostname. The code then ...[truncated 2693 chars]
Remediation
View remediation
str: parsed = urlparse(value) if parsed.scheme != "https": raise ValueError("CalDAV endpoint must use HTTPS") if parsed.username or parsed.password: raise ValueError("CalDAV endpoint must not contain user information") if (parsed.hostname or "").lower() != "caldav.icloud.com": raise ValueError("Unapproved CalDAV endpoint") return value ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
src/icalendar_sync/calendar.py:802
Finding

HTTP debug diagnostics may expose Apple session tokens and sensitive response data

Content
View full analysis
None: debug_data = { "status": str(getattr(response, "status_code", "")), "reason": str(getattr(response, "reason", "")), "url": str(getattr(response, "url", "")), } headers = getattr(response, "headers", {}) for key in ("x-apple-request-id", "x-apple-session-token", "www-authenticate", "location"): value = headers.get(key) or headers.get(key.title()) if value: debug_data[key] = str(value) if self.debug_http: body = sanitize_text(getattr(response, "text", "") or "", 2000) if body: debug_data["body"] = body self._last_http_debug = debug_data ``` ```python def _debug_string_from_last_response(self) -> str: if not self._last_http_debug: return "" order = [ "status", "reason", "url", "x-apple-request-id", "x-apple-session-token", "www-authenticate", "location", "body", ] return ", ".join( f"{key}={self._last_http_debug[key]}" for key in order if self._last_http_debug.get(key) ) ``` ```python except AuthorizationError as exc: print("❌ Authentication failed: invalid credentials or blocked iCloud request") if self.debug_http and self._debug_string_from_last_response(): print(f" Apple response: {self._debug_string_from_last_response()}") if self.debug_http: print(f" Debug: {self._format_exception_details(exc)}") logger.error("Authentication failed (%s)", self._format_exception_details(exc)) self._connected = False return False ``` The same response-debug printing pattern is used for TLS, netwo ...[truncated 2490 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:2
Finding

Installation uses non-reproducible dependency ranges without integrity hashes

Content
View full analysis
=1.3.0,<2.0.0 icalendar>=5.0.0,<6.0.0 pyyaml>=6.0,<7.0 python-dateutil>=2.8.0,<3.0.0 # Security: Updated to fix CVE-2023-32681 requests>=2.31.0,<3.0.0 # Secure credential storage keyring>=24.0.0,<25.0.0 # Timezone support (Python 3.9+, backport for 3.8) backports.zoneinfo>=0.2.1,<1.0.0; python_version < "3.9" ``` ```bash # Install dependencies with error checking echo "📥 Installing dependencies..." if python3 -m pip install -r "$SKILL_DIR/requirements.txt"; then echo "✓ Dependencies installed successfully" else echo "❌ Error: Failed to install dependencies" echo " Please check your Python environment and try again" exit 1 fi ``` ### Technical Analysis The installer resolves dependencies from broad compatible version ranges at installation time. It does not use an audited lock file, exact versions, package hashes, or `pip --require-hashes`. No typosquatted dependency, nonstandard package index, or known malicious dependency was identified in the audited manifests. The risk instead arises because the actual code installed in the future may differ from the dependency versions represented during this review. Python package installation can execute build-backend code, and installed dependencies execute within the calendar process at runtime. A compromised package release, compromised package index account, or unexpectedly incompatible future release satisfying one of these ranges could therefore become part of the effective Skill without changes to this repository. ### Attack Path 1. A dependency publisher account or package-distribution channel is compromised, or a malicious compatible release is otherwise made available. 2. The malicious version remains within one of t ...[truncated 998 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (189)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code does not perform calendar operations, CalDAV/macOS bridge access, credential setup, keyring access, event CRUD, or recurring event handling. It only provides multilingual text resources and helper functions for selecting and formatting translations. Although many strings reference calendar and credential workflows, the actual executable behavior in this chunk is limited to i18n support. That is a materially different primary purpose from the declared description, so this chunk is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description describes a full-featured calendar integration skill. The actual code chunk is only a test module initializer and does not implement any of the stated capabilities. Its apparent purpose is test-package organization for 'iCalendar Sync,' which is materially different from an operational calendar skill. Therefore this is a clear description-behavior mismatch based on the provided code.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/calendar.py (reported line 70)May include surrounding context.

python
except ImportError as exc:  # pragma: no cover - depends on runtime environment
    CALDAV_IMPORT_ERROR = str(exc)

KEYRING_IMPORT_ERROR = ""
keyring = None
KeyringError = Exception
try:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/calendar.py (reported line 77)May include surrounding context.

python
except ImportError as exc:  # pragma: no cover - depends on runtime environment
    CALDAV_IMPORT_ERROR = str(exc)

KEYRING_IMPORT_ERROR = ""
keyring = None
KeyringError = Exception
try:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/calendar.py (reported line 83)May include surrounding context.

python
except ImportError as exc:  # pragma: no cover - depends on runtime environment
    CALDAV_IMPORT_ERROR = str(exc)

KEYRING_IMPORT_ERROR = ""
keyring = None
KeyringError = Exception
try:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/calendar.py (reported line 86)May include surrounding context.

python
except ImportError as exc:  # pragma: no cover - depends on runtime environment
    CALDAV_IMPORT_ERROR = str(exc)

KEYRING_IMPORT_ERROR = ""
keyring = None
KeyringError = Exception
try:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/calendar.py (reported line 762)May include surrounding context.

python
except ImportError as exc:  # pragma: no cover - depends on runtime environment
    CALDAV_IMPORT_ERROR = str(exc)

KEYRING_IMPORT_ERROR = ""
keyring = None
KeyringError = Exception
try:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/calendar.py (reported line 770)May include surrounding context.

python
except ImportError as exc:  # pragma: no cover - depends on runtime environment
    CALDAV_IMPORT_ERROR = str(exc)

KEYRING_IMPORT_ERROR = ""
keyring = None
KeyringError = Exception
try:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/calendar.py (reported line 771)May include surrounding context.

python
except ImportError as exc:  # pragma: no cover - depends on runtime environment
    CALDAV_IMPORT_ERROR = str(exc)

KEYRING_IMPORT_ERROR = ""
keyring = None
KeyringError = Exception
try:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/calendar.py (reported line 1725)May include surrounding context.

python
except ImportError as exc:  # pragma: no cover - depends on runtime environment
    CALDAV_IMPORT_ERROR = str(exc)

KEYRING_IMPORT_ERROR = ""
keyring = None
KeyringError = Exception
try:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/calendar.py (reported line 1727)May include surrounding context.

python
except ImportError as exc:  # pragma: no cover - depends on runtime environment
    CALDAV_IMPORT_ERROR = str(exc)

KEYRING_IMPORT_ERROR = ""
keyring = None
KeyringError = Exception
try:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/calendar.py (reported line 1750)May include surrounding context.

python
except ImportError as exc:  # pragma: no cover - depends on runtime environment
    CALDAV_IMPORT_ERROR = str(exc)

KEYRING_IMPORT_ERROR = ""
keyring = None
KeyringError = Exception
try:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 26)May include surrounding context.

md
'are_you_sure': '이것이 맞습니까? (y/n): ',
        'setup_cancelled': '설정이 취소되었습니다',
        'credentials_saved_keyring': '✅ 자격 증명이 시스템 키체인에 안전하게 저장되었습니다',
        'keyring_fallback': '⚠️  시스템 키체인에 액세스할 수 없습니다. .env 파일로 대체합니다',
        'credentials_saved_file': '✅ 구성이 {path}에 안전하게 저장되었습니다',
        'ready_to_use': '🚀 이제 iCalendar Sync를 사용할 수 있습니다!',
        'available_calendars': '📅 사용 가능한 일정 ({count}): ',

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/i18n.py (reported line 36)May include surrounding context.

python
'are_you_sure': '이것이 맞습니까? (y/n): ',
        'setup_cancelled': '설정이 취소되었습니다',
        'credentials_saved_keyring': '✅ 자격 증명이 시스템 키체인에 안전하게 저장되었습니다',
        'keyring_fallback': '⚠️  시스템 키체인에 액세스할 수 없습니다. .env 파일로 대체합니다',
        'credentials_saved_file': '✅ 구성이 {path}에 안전하게 저장되었습니다',
        'ready_to_use': '🚀 이제 iCalendar Sync를 사용할 수 있습니다!',
        'available_calendars': '📅 사용 가능한 일정 ({count}): ',

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/translations_extended.py (reported line 24)May include surrounding context.

python
'are_you_sure': '이것이 맞습니까? (y/n): ',
        'setup_cancelled': '설정이 취소되었습니다',
        'credentials_saved_keyring': '✅ 자격 증명이 시스템 키체인에 안전하게 저장되었습니다',
        'keyring_fallback': '⚠️  시스템 키체인에 액세스할 수 없습니다. .env 파일로 대체합니다',
        'credentials_saved_file': '✅ 구성이 {path}에 안전하게 저장되었습니다',
        'ready_to_use': '🚀 이제 iCalendar Sync를 사용할 수 있습니다!',
        'available_calendars': '📅 사용 가능한 일정 ({count}): ',

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/translations_extended.py (reported line 87)May include surrounding context.

python
'are_you_sure': '이것이 맞습니까? (y/n): ',
        'setup_cancelled': '설정이 취소되었습니다',
        'credentials_saved_keyring': '✅ 자격 증명이 시스템 키체인에 안전하게 저장되었습니다',
        'keyring_fallback': '⚠️  시스템 키체인에 액세스할 수 없습니다. .env 파일로 대체합니다',
        'credentials_saved_file': '✅ 구성이 {path}에 안전하게 저장되었습니다',
        'ready_to_use': '🚀 이제 iCalendar Sync를 사용할 수 있습니다!',
        'available_calendars': '📅 사용 가능한 일정 ({count}): ',

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/translations_extended.py (reported line 150)May include surrounding context.

python
'are_you_sure': '이것이 맞습니까? (y/n): ',
        'setup_cancelled': '설정이 취소되었습니다',
        'credentials_saved_keyring': '✅ 자격 증명이 시스템 키체인에 안전하게 저장되었습니다',
        'keyring_fallback': '⚠️  시스템 키체인에 액세스할 수 없습니다. .env 파일로 대체합니다',
        'credentials_saved_file': '✅ 구성이 {path}에 안전하게 저장되었습니다',
        'ready_to_use': '🚀 이제 iCalendar Sync를 사용할 수 있습니다!',
        'available_calendars': '📅 사용 가능한 일정 ({count}): ',

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/translations_extended2.py (reported line 23)May include surrounding context.

python
'are_you_sure': '이것이 맞습니까? (y/n): ',
        'setup_cancelled': '설정이 취소되었습니다',
        'credentials_saved_keyring': '✅ 자격 증명이 시스템 키체인에 안전하게 저장되었습니다',
        'keyring_fallback': '⚠️  시스템 키체인에 액세스할 수 없습니다. .env 파일로 대체합니다',
        'credentials_saved_file': '✅ 구성이 {path}에 안전하게 저장되었습니다',
        'ready_to_use': '🚀 이제 iCalendar Sync를 사용할 수 있습니다!',
        'available_calendars': '📅 사용 가능한 일정 ({count}): ',

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/i18n.py (reported line 99)May include surrounding context.

python
'are_you_sure': 'Tem a certeza que está correto? (s/n): ',
        'setup_cancelled': 'Configuração cancelada',
        'credentials_saved_keyring': '✅ Credenciais guardadas com segurança no porta-chaves do sistema',
        'keyring_fallback': '⚠️  Não foi possível aceder ao porta-chaves do sistema, a usar ficheiro .env',
        'credentials_saved_file': '✅ Configuração guardada com segurança em {path}',
        'ready_to_use': '🚀 Já pode usar o iCalendar Sync!',
        'available_calendars': '📅 Calendários Disponíveis ({count}):',

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/i18n.py (reported line 414)May include surrounding context.

python
'are_you_sure': 'Tem a certeza que está correto? (s/n): ',
        'setup_cancelled': 'Configuração cancelada',
        'credentials_saved_keyring': '✅ Credenciais guardadas com segurança no porta-chaves do sistema',
        'keyring_fallback': '⚠️  Não foi possível aceder ao porta-chaves do sistema, a usar ficheiro .env',
        'credentials_saved_file': '✅ Configuração guardada com segurança em {path}',
        'ready_to_use': '🚀 Já pode usar o iCalendar Sync!',
        'available_calendars': '📅 Calendários Disponíveis ({count}):',

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/i18n.py (reported line 481)May include surrounding context.

python
'are_you_sure': 'Tem a certeza que está correto? (s/n): ',
        'setup_cancelled': 'Configuração cancelada',
        'credentials_saved_keyring': '✅ Credenciais guardadas com segurança no porta-chaves do sistema',
        'keyring_fallback': '⚠️  Não foi possível aceder ao porta-chaves do sistema, a usar ficheiro .env',
        'credentials_saved_file': '✅ Configuração guardada com segurança em {path}',
        'ready_to_use': '🚀 Já pode usar o iCalendar Sync!',
        'available_calendars': '📅 Calendários Disponíveis ({count}):',

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/translations_extended2.py (reported line 86)May include surrounding context.

python
'are_you_sure': 'Tem a certeza que está correto? (s/n): ',
        'setup_cancelled': 'Configuração cancelada',
        'credentials_saved_keyring': '✅ Credenciais guardadas com segurança no porta-chaves do sistema',
        'keyring_fallback': '⚠️  Não foi possível aceder ao porta-chaves do sistema, a usar ficheiro .env',
        'credentials_saved_file': '✅ Configuração guardada com segurança em {path}',
        'ready_to_use': '🚀 Já pode usar o iCalendar Sync!',
        'available_calendars': '📅 Calendários Disponíveis ({count}):',

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/icalendar_sync/translations_extended2.py (reported line 149)May include surrounding context.

python
'are_you_sure': 'Tem a certeza que está correto? (s/n): ',
        'setup_cancelled': 'Configuração cancelada',
        'credentials_saved_keyring': '✅ Credenciais guardadas com segurança no porta-chaves do sistema',
        'keyring_fallback': '⚠️  Não foi possível aceder ao porta-chaves do sistema, a usar ficheiro .env',
        'credentials_saved_file': '✅ Configuração guardada com segurança em {path}',
        'ready_to_use': '🚀 Já pode usar o iCalendar Sync!',
        'available_calendars': '📅 Calendários Disponíveis ({count}):',

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 102)May include surrounding context.

md
import sys
from datetime import datetime, timezone
from unittest.mock import patch
from keyring.errors import KeyringError
import pytest

sys.path.insert(0, os.path.join(os.path.dirname(__file__), "..", "src"))

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 107)May include surrounding context.

sh
import sys
from datetime import datetime, timezone
from unittest.mock import patch
from keyring.errors import KeyringError
import pytest

sys.path.insert(0, os.path.join(os.path.dirname(__file__), "..", "src"))

Static analysis

No suspicious patterns detected.