Back to skill

Security audit

Gcalcli Calendar 3.0.0

Security checks for vulnerabilities and agentic risk

Overview

This calendar skill is transparent about using gcalcli, but its shell command templates and no-confirmation deletes create Review-level risk if installed as-is.

Install only if you are comfortable giving an agent access to read and modify your Google Calendar through gcalcli. Before using it, prefer adding a confirmation step for all deletes/edits, pin and verify the gcalcli dependency, and ensure any command execution path safely passes arguments instead of interpolating calendar titles, queries, or calendar names into a shell string.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:108
Finding

Shell Command Injection Through Unsafely Interpolated Calendar Values

Content
View full analysis
" today +180d` - Custom: `gcalcli --nocolor search "" ` ``` ```text - Timed event: - `gcalcli --nocolor --calendar "" add --noprompt --title "" --when "<Start>" --duration <minutes>` - All-day event: - `gcalcli --nocolor --calendar "<Cal>" add --noprompt --allday --title "<Title>" --when "<Date>"` ``` ```sh echo 'BEGIN:VCALENDAR VERSION:2.0 BEGIN:VEVENT DTSTART;VALUE=DATE:20260308 SUMMARY:Event Title RRULE:FREQ=YEARLY TRANSP:TRANSPARENT END:VEVENT END:VCALENDAR' | gcalcli import --calendar "<Cal>" ``` ```text - Delete (non-interactive, bounded): - `gcalcli --nocolor delete --iamaexpert "<query>" <start> <end>` ``` ### Technical Analysis The documented command templates interpolate calendar names, event titles, search terms, dates, and other potentially user-controlled values directly into shell command text. Surrounding values with double quotes does not make a dynamically constructed shell command safe: shell metacharacters such as command substitutions can become executable syntax when the completed command string is parsed by a shell. The ICS import example is additionally built using a single-quoted `echo` payload. An apostrophe introduced into an event title or another ICS field can terminate the quoted string and permit additional shell syntax. The Skill does not require use of a shell-free argument-array API, robust shell escaping, or validation of control characters. Calendar data can also originate from shared or externally controlled calendars. Reusing an attacker-controlled event value in a later generated command can therefore create a stored injection path, depending on how the hosting agent constructs and executes commands. ### Attack Path 1. An attacker supplie ...[truncated 1272 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:16
Finding

Unpinned Third-Party CLI Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The skill's stated policy is to skip user confirmation for destructive actions like delete/edit. Even though framed as a UX optimization, this is a genuine safety weakness because it allows irreversible changes based solely on the agent's interpretation of conversational input, increasing the chance of accidental or manipulated deletion of calendar data.

Content

Scanner excerpt · README.md (reported line 23)May include surrounding context.

md
**This skill intentionally skips user confirmation for unambiguous destructive actions (delete/edit).** This is a deliberate UX decision, not an oversight. Here's why and how it's kept safe:

### Why skip confirmation?

This skill is designed for personal assistant use via messaging apps (Telegram, WhatsApp, etc.), where:
- The user has already stated their intent explicitly (e.g. "delete my dentist appointment on Thursday").

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The README explicitly authorizes destructive calendar actions to proceed without a separate confirmation step when the agent judges the request to be unambiguous. That creates a real autonomous-decision risk: natural-language ambiguity, incorrect event matching, prompt injection through conversation context, or mistaken date interpretation could cause unintended deletion or edits to a user's calendar. The surrounding safeguards reduce risk, but they do not eliminate the core issue that the agent is empowered to perform destructive actions based on its own interpretation.

Content

Scanner excerpt · README.md (reported line 32)May include surrounding context.

md
### Safety guards in place

The skill does NOT blindly delete. All of these must hold before executing without confirmation:

1. **Explicit user request** — the user must have asked for the action in their message.
2. **Single unambiguous match** — exactly one event matches in a tight, bounded time window.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 36)May include surrounding context.

md
1. **Explicit user request** — the user must have asked for the action in their message.
2. **Single unambiguous match** — exactly one event matches in a tight, bounded time window.
3. **Post-action verification** — after every delete, the agent verifies via agenda that the event is actually gone. It never claims success without verification.
4. **Disambiguation for ambiguous cases** — if multiple events match, the agent always stops and asks the user to choose before proceeding.
5. **Overlap checks for creates** — before creating events, the agent checks for scheduling conflicts across all calendars and asks for confirmation if an overlap exists.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly permits destructive calendar actions to proceed without an additional user-facing warning when it decides the match is unambiguous. In a calendar-management context, deletion is irreversible from the assistant's perspective and mistakes in matching, phrasing, or tool output could remove the wrong event without giving the user a final chance to stop it.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

The skill authorizes autonomous execution of delete/edit actions without confirmation once the agent judges the request unambiguous. That creates a real risk of erroneous state-changing actions because semantic matching, date resolution, and agenda scans can be wrong or incomplete, and the user is denied a last verification step before destruction.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
This skill is designed for personal assistant use where the user expects fast, low-friction calendar management. The confirmation policy below is an intentional UX choice — see README.md for rationale and safety guards.

### Unambiguous actions: execute immediately
For cancel/delete/edit actions, skip confirmation when ALL of these hold:
- The user explicitly requested the action (e.g. "delete my dentist appointment").
- Exactly one event matches in a tight time window.
- The match is unambiguous (single clear result on an exact date, or user specified date+time).

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction "Don't mix languages within one reply" imposes a language-output constraint in natural language. Because the file does not indicate that the user can choose language behavior or opt into this restriction, it may conflict with language/locale choice policy.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
- Don't quote event titles unless needed to disambiguate.

### Calendar scope
- Trust gcalcli config (default/ignore calendars). Don't broaden scope unless user asks "across all calendars" or results are clearly wrong.

### Agenda (today-only by default)
- If user asks "agenda" without a period, return today only.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill instructs the agent to inspect all non-ignored calendars for overlap detection even when creating into a specific calendar, but it does not require informing the user that multiple calendars may be queried. This can expose metadata from calendars the user did not expect to be consulted, creating a privacy and least-surprise issue rather than a direct integrity compromise.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.