Calendar

Security checks across malware telemetry and agentic risk

Overview

This small calendar skill is purpose-aligned and has no executable code, but users should review any calendar access or event changes it enables.

Before installing, confirm you trust the publisher and review any provider authorization prompts. Treat creating events, sending invites, showing availability, and syncing calendars as sensitive actions that should be explicitly approved before the agent performs them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The usage examples are broad natural-language phrases that closely resemble ordinary user conversation, without an explicit invocation boundary or trigger format. This can cause accidental activation or unintended execution of calendar actions when a user is merely discussing plans, which is more sensitive here because the skill can create events, manage meetings, and expose availability data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal