Back to skill

Security audit

日历管理技能专业版

Security checks across malware telemetry and agentic risk

Overview

This calendar skill is not clearly malicious, but it asks agents to use broad command and file capabilities beyond normal calendar management.

Review this skill before installing. Use it only if you are comfortable granting an agent authenticated calendar access plus local command and file-search tools, and restrict use to explicit calendar tasks such as viewing, creating, exporting, or auditing events. Avoid using it for vague automation requests unless the commands, files, profiles, calendars, and webhook destinations are clearly specified.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is marketed as a calendar-management tool, but its documented capabilities expand into generic file processing, API integration, and command execution. That scope expansion increases the chance an agent will use powerful tools outside the user’s expected intent, enabling unintended data access or execution paths if invoked loosely.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
Including generic command-execution capability in a calendar skill violates least privilege and creates unnecessary attack surface. If the agent maps user requests to this skill, an attacker could potentially steer the model into running unrelated shell commands under the guise of calendar operations.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
Documenting broad file read/write handling for a calendar skill gives the agent capabilities unrelated to its stated purpose. In practice, this can enable unauthorized local data access or modification if prompts are ambiguous or adversarially crafted.

Vague Triggers

Medium
Confidence
85% confidence
Finding
Overly broad triggering guidance increases the likelihood the skill will activate for vague requests and gain access to powerful tools unnecessarily. In a skill that also advertises exec/read/grep/glob capabilities, accidental or adversarial invocation becomes more dangerous because it can route benign-seeming prompts into high-privilege behavior.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example invocation phrase is too generic and can cause the agent to select this skill for loosely related tasks. Because the skill exposes privileged tooling and broad automation claims, generic invocation language materially raises the risk of unintended execution or data access.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.