Back to skill

Security audit

calendar-skill-tool-free

Security checks across malware telemetry and agentic risk

Overview

The skill is a calendar automation helper, but it combines calendar write/delete authority and credentialed external services with broad triggers and unclear privacy wording.

Review this skill before installing. Use it only if you are comfortable granting an agent command-line access to a credentialed calendar CLI, and require manual confirmation before creating, updating, deleting, or notifying attendees. Treat the local-only privacy claim as unreliable unless the publisher clarifies exactly what calendar data and credentials are sent to porteden, Google, Outlook, or other external APIs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The document claims the FREE version stores all data locally and does not upload to the cloud, yet elsewhere it requires authentication to external services and states that some features need network access to external APIs. This mismatch can mislead users about where their calendar data and credentials are processed, causing unsafe trust decisions and privacy/compliance issues.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger conditions are overly broad and mismatched to the skill's actual calendar scope, which can cause the agent to invoke this skill for unrelated data analysis or reporting requests. In a skill with exec capability and calendar write/delete actions, misrouting increases the chance of unintended command execution or unintended modification of calendar data.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill includes state-changing operations such as creating, updating, and deleting events but does not consistently require explicit confirmation before execution. In an agentic context with exec enabled, ambiguous natural-language requests or prompt injection in surrounding context could lead to unauthorized or accidental calendar modifications affecting schedules, attendees, and notifications.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.