Google Calendar

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Google Calendar integration that discloses account connection and calendar read/write abilities, though users should be careful with event changes and raw API proxy use.

Install only if you trust Membrane and are comfortable connecting the intended Google account. Review the OAuth permissions, prefer predefined actions over raw proxy requests, and require explicit confirmation before creating, updating, or deleting calendar events.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is broad enough that an agent may invoke it for loosely related requests involving communication, records, or workflows rather than clearly bounded Google Calendar tasks. In an agentic setting, vague routing criteria can cause overbroad tool use against a connected calendar account, increasing the chance of unnecessary data access or unintended actions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises destructive actions like deleting and updating events without any accompanying requirement for confirmation, dry-run behavior, or warning about irreversible effects. In a calendar context, this can lead to accidental loss or corruption of scheduling data if an agent selects these actions autonomously or from ambiguous user input.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal