Back to skill

Security audit

brainz-calendar-tool-free

Security checks across malware telemetry and agentic risk

Overview

This calendar skill is mostly purpose-aligned, but it can modify real calendar data and handles external calendar credentials while giving inconsistent and under-scoped privacy and integration guidance.

Review this skill before installing. It is not clearly malicious, but only use it if you are comfortable granting an agent command-line access to your calendar tooling. Use scoped credentials where possible, avoid putting secrets in prompts or logs, and require the agent to preview calendar deletions before making changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill claims FREE users can use CalDAV backup in one section, but elsewhere limits CalDAV support to PRO. This inconsistency can mislead an agent or user into attempting unsupported external sync or credential handling flows, increasing the chance of improper configuration, accidental data exposure, or unsafe fallback behavior.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The document states that all data is stored locally and not uploaded to the cloud, yet the skill is explicitly designed to interact with Google Calendar and external APIs. This is a materially misleading privacy claim that could cause users to expose sensitive calendar data under false assumptions about network transmission and storage.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The skill says FREE supports only Google Calendar while PRO supports Google/Apple/Outlook and CalDAV, directly contradicting earlier FREE CalDAV backup claims. Contradictory support boundaries create unsafe ambiguity around what endpoints, credentials, and network operations an agent may attempt.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger condition says to use the skill for data analysis, reporting, statistics, and visualization, which does not match the actual calendar-management functions described elsewhere. Overbroad and inaccurate triggering can cause the agent to invoke this skill in unintended contexts, leading to unnecessary command execution or calendar modifications.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The natural-language trigger guidance is too generic and lacks boundaries on when the skill should activate. In an exec-enabled skill that can create or delete calendar events, vague activation text raises the risk of accidental invocation and unintended side effects.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises deletion of events and command-line execution capability without clear warnings about destructive actions, account impact, or confirmation requirements. In context, this is more dangerous because calendar deletions affect real user data and the skill has exec access to perform those actions directly.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document instructs users to configure API keys and CalDAV credentials and to use external services, but it does not clearly disclose data transmission, credential handling, or privacy implications. This omission can cause users to provide sensitive secrets without understanding where they are sent, stored, or logged.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.