T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party CLI Receives Sensitive Calendar Access
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a clear calendar-management wrapper for the Porteden CLI, with disclosed credential handling and confirmation required before calendar changes.
Install only if you trust Porteden with the selected calendar account. Prefer narrow OAuth scopes and a dedicated profile, confirm all create/update/delete/respond actions carefully, avoid --all unless needed, and run porteden auth logout plus provider-side revocation when finished on shared or sensitive machines.
SKILL.md:5Unpinned Third-Party CLI Receives Sensitive Calendar Access
SKILL.md:14Undisclosed Network Trust Boundary for Credentials and Calendar Data
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Setup (once)
- **Browser login (recommended):** `porteden auth login` — opens browser, credentials stored in system keyring
- **Direct token:** `porteden auth login --token <key>` — stored in system keyring
- **Verify:** `porteden auth status`
- If `PE_API_KEY` is set in the environment, the CLI uses it automatically (no login needed).
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Setup (once)
- **Browser login (recommended):** `porteden auth login` — opens browser, credentials stored in system keyring
- **Direct token:** `porteden auth login --token <key>` — stored in system keyring
- **Verify:** `porteden auth status`
- If `PE_API_KEY` is set in the environment, the CLI uses it automatically (no login needed).
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Setup (once)
- **Browser login (recommended):** `porteden auth login` — opens browser, credentials stored in system keyring
- **Direct token:** `porteden auth login --token <key>` — stored in system keyring
- **Verify:** `porteden auth status`
- If `PE_API_KEY` is set in the environment, the CLI uses it automatically (no login needed).
No suspicious patterns detected.