Back to skill

Security audit

Dingtalk Calendar

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed DingTalk calendar helper, but it can read coworker availability/contact data and change calendar entries, so it should be used with authorization and confirmations.

Install only if you intend to connect the agent to DingTalk calendar and contacts. Verify the mcporter package and DingTalk MCP URLs, use an account with the least necessary permissions, and require an explicit preview and confirmation before changing events, deleting events, booking rooms, or checking another person's availability.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The changelog advertises contact-directory search and user-detail lookup capabilities that expand beyond the stated calendar and meeting-management scope. This kind of scope mismatch is security-relevant because it can hide access to broader employee directory data, increasing privacy and authorization risks if users or reviewers assume the skill only handles scheduling functions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill encourages querying other users' busy/free status without any guidance about authorization, consent, or organizational policy. In a calendar/contacts integration, this can enable privacy-invasive lookups or unauthorized reconnaissance on employee schedules if the operator or service has broad permissions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill exposes a destructive delete operation with no caution, confirmation guidance, or scoping advice. In practice, this increases the chance of accidental or unauthorized event deletion, which can disrupt meetings, erase scheduling records, and impact multiple attendees or reserved rooms.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrase "创建日程" is broad and maps to a common natural-language scheduling request, so the skill may be invoked unintentionally when a user is speaking generally rather than explicitly selecting this integration. Because this skill can perform state-changing calendar actions, accidental activation could lead to unwanted event creation, updates, or follow-on access to scheduling data.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger phrase "会议预订" is ambiguous because it does not clearly indicate DingTalk or even whether the user wants a calendar skill versus some other booking workflow. In an agent environment, ambiguous triggers can cause over-broad routing and unintended use of a capability that can read calendars, check others' availability, or reserve resources.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrase "查询闲忙" is especially broad for a skill that can query other users' free/busy status, making accidental or overly eager invocation more risky in context. Even if the underlying platform enforces permissions, loose matching increases the chance of unnecessary exposure of scheduling metadata or confusing cross-skill behavior.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.