Back to skill

Security audit

Calendar Reminder Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Outlook-to-Feishu calendar reminder workflow with persistent scheduling, but no hidden or destructive behavior was found.

Before installing, confirm you are comfortable sending Outlook meeting subjects, times, organizers, and locations to Feishu every day. Review the cron command before running it, test manually first, and use the documented pause/resume/list commands if you do not want the task to keep running.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill directs users to automatically scan Outlook calendar contents and send reminders/report data to Feishu, but it does not give a clear privacy warning about what calendar metadata will be transmitted, how often it will be sent, or the sensitivity of meeting subjects, locations, and organizers. This is dangerous because users may enable ongoing exfiltration of personal or work scheduling data to a third-party messaging platform without informed consent or data-minimization safeguards.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The cron registration steps create a persistent scheduled task that automatically runs a local script and transmits calendar-derived data, but the instructions do not clearly warn that the job will continue running daily until removed or paused. This is risky because users may unknowingly establish continuous collection and forwarding of sensitive schedule information, increasing the chance of privacy leakage and long-term unintended data exposure.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.