Vivocalendar

Security checks across malware telemetry and agentic risk

Overview

This is a real Vivocalendar integration, but it gives an agent broad authenticated API access that can change or delete calendar and contact data without clear confirmation guardrails.

Install only if you are comfortable connecting Vivocalendar through Membrane. Prefer prebuilt Membrane actions, review the permissions granted during login, and require the agent to ask before creating, updating, or deleting calendar events or contacts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill documents direct proxy access to arbitrary API paths and explicitly supports mutating HTTP methods like POST, PUT, PATCH, and DELETE without warning about destructive effects or requiring confirmation. In an agent setting, this increases the chance of unintended data changes or deletion if the model chooses raw requests instead of safer prebuilt actions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal