Back to skill

Security audit

Mermail Scheduling Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed scheduling assistant that uses Mermail and Google Calendar with clear approval gates for email sends and calendar writes.

Install only if you intend to let the agent work with a Mermail mailbox and a connected Google Calendar. Review previews carefully before approving event creation, mailbox creation, drafts, scheduled sends, or confirmation emails.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The default_prompt uses broad routing language ('when the job is scheduling, checking calendar availability, offering slots, or confirming a meeting') that can cause the agent to be invoked for loosely related requests. Because this skill connects to a live Mermail mailbox and Google Calendar, unintended invocation could expose email/calendar context or trigger actions in higher-risk situations than intended.

Static analysis

No suspicious patterns detected.