Back to skill

Security audit

Google Calendar (via gcalcli)

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its calendar-management purpose, but it should be reviewed because it can delete or edit calendar events without a second confirmation and its shell command templates are not safely scoped against injected calendar text.

Install only if you are comfortable letting the agent make Google Calendar changes through your local gcalcli OAuth profile. Prefer requiring confirmation before any delete/edit action, and avoid using raw shell command strings with untrusted event titles, calendar names, or queries; a safer implementation should pass gcalcli arguments as structured argv and escape ICS fields correctly.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:116
Finding

Shell Command Injection Through Unescaped Calendar Data

Content
View full analysis
" add --noprompt --title "" --when "<Start>" --duration <minutes> gcalcli --nocolor --calendar "<Cal>" add --noprompt --allday --title "<Title>" --when "<Date>" ``` ```sh echo 'BEGIN:VCALENDAR VERSION:2.0 BEGIN:VEVENT DTSTART;VALUE=DATE:20260308 SUMMARY:Event Title RRULE:FREQ=YEARLY TRANSP:TRANSPARENT END:VEVENT END:VCALENDAR' | gcalcli import --calendar "<Cal>" ``` ```sh gcalcli --nocolor delete --iamaexpert "<query>" <start> <end> ``` ### Technical Analysis The Skill directs the agent to interpolate calendar names, event titles, dates, search queries, durations, and generated ICS content into shell command strings. It does not require argument-array execution, strict input validation, or shell-safe escaping. Double quotes do not neutralize all shell syntax. If a dynamic value contains a double quote followed by shell operators, it may terminate the intended argument and append another command. The multiline `echo` pattern is also unsafe when generated ICS data contains a single quote, because that character can terminate the shell's single-quoted string. The risk applies to values supplied directly by a user and potentially to text retrieved from calendar events and later reused in commands. Whether exploitation succeeds depends on the execution tool invoking these templates through a shell. If commands are executed as structured argument arrays without shell parsing, the shell-injection path is prevented. The ICS template has an additional data-integrity concern: dynamically generated text fields should be escaped according to RFC 5545, independently of shell escaping. ### Attack Path 1. An attacker supplies an event title, calendar name, or deletion query containing quote-breaking charact ...[truncated 1344 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:16
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

The README states that the skill intentionally skips user confirmation for unambiguous destructive actions such as delete and edit. Even if framed as a UX decision, this delegates destructive authority to the agent and increases the chance of accidental or manipulated actions when event matching, time interpretation, or user intent resolution is wrong.

Content

Scanner excerpt · README.md (reported line 23)May include surrounding context.

md
**This skill intentionally skips user confirmation for unambiguous destructive actions (delete/edit).** This is a deliberate UX decision, not an oversight. Here's why and how it's kept safe:

### Why skip confirmation?

This skill is designed for personal assistant use via messaging apps (Telegram, WhatsApp, etc.), where:
- The user has already stated their intent explicitly (e.g. "delete my dentist appointment on Thursday").

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The skill explicitly permits deletion of calendar events without a separate confirmation step once it decides the request is explicit and the match is unambiguous. That creates autonomous destructive behavior based on the agent's interpretation of natural language, which can fail due to ambiguity, misparsing, or adversarial prompting, leading to unintended event deletion.

Content

Scanner excerpt · README.md (reported line 32)May include surrounding context.

md
### Safety guards in place

The skill does NOT blindly delete. All of these must hold before executing without confirmation:

1. **Explicit user request** — the user must have asked for the action in their message.
2. **Single unambiguous match** — exactly one event matches in a tight, bounded time window.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 36)May include surrounding context.

md
1. **Explicit user request** — the user must have asked for the action in their message.
2. **Single unambiguous match** — exactly one event matches in a tight, bounded time window.
3. **Post-action verification** — after every delete, the agent verifies via agenda that the event is actually gone. It never claims success without verification.
4. **Disambiguation for ambiguous cases** — if multiple events match, the agent always stops and asks the user to choose before proceeding.
5. **Overlap checks for creates** — before creating events, the agent checks for scheduling conflicts across all calendars and asks for confirmation if an overlap exists.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly allows delete/edit actions to proceed without a user-facing confirmation when it deems the match unambiguous. Even with bounded windows and post-delete verification, a mistaken match, ambiguous natural-language interpretation, or stale calendar state could cause irreversible deletion of the wrong event.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

This is a genuine autonomy risk: the skill instructs the agent to skip confirmation for destructive actions based on its own determination of unambiguity. In a calendar tool, misresolution of dates, titles, or duplicate events can directly lead to unintended deletions or delete-and-recreate modifications.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
This skill is designed for personal assistant use where the user expects fast, low-friction calendar management. The confirmation policy below is an intentional UX choice — see README.md for rationale and safety guards.

### Unambiguous actions: execute immediately
For cancel/delete/edit actions, skip confirmation when ALL of these hold:
- The user explicitly requested the action (e.g. "delete my dentist appointment").
- Exactly one event matches in a tight time window.
- The match is unambiguous (single clear result on an exact date, or user specified date+time).

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction "Don't mix languages within one reply" imposes a language-format constraint regardless of user preference. Under the policy, language or locale constraints should either offer user choice or be clearly justified as region-specific, which is not present here.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
- Don't quote event titles unless needed to disambiguate.

### Calendar scope
- Trust gcalcli config (default/ignore calendars). Don't broaden scope unless user asks "across all calendars" or results are clearly wrong.

### Agenda (today-only by default)
- If user asks "agenda" without a period, return today only.

Static analysis

No suspicious patterns detected.