Back to skill

Security audit

日历技能

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a calendar-management skill, but its documentation is materially inconsistent and under-scoped for sensitive calendar access.

Review this skill carefully before installing. It may be intended for calendar management, but the documentation mixes unrelated security-audit claims with broad project-management triggers and requests broad agent tools. Only use it with explicit calendar tasks, avoid sharing sensitive event details unless provider permissions and data handling are clarified, and require confirmation before creating, modifying, or syncing calendar events.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The documented JSON response describes a grading or audit report with fields like overall_grade, total_score, and code-style/security scoring, which is inconsistent with a calendar-management skill. This kind of mismatched interface can cause an agent to mis-handle outputs, route sensitive calendar data into the wrong workflow, or trust fabricated 'security' results instead of actual scheduling outcomes.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The FAQ claims paid features such as CVE correlation, compliance auditing, asset risk scoring, and threat-intelligence alerts, which are unrelated to calendar functionality. This scope contradiction can mislead agents or users into invoking the skill for security-analysis tasks it should not perform, increasing the chance of inappropriate data collection, unsafe trust decisions, or incorrect operational use.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation guidance is overly broad, suggesting use for project management, task planning, progress tracking, and team collaboration rather than narrowly scoped calendar actions. Overbroad matching can cause an agent to invoke this skill on unrelated prompts, potentially sending unnecessary user or organizational data to external calendar-connected workflows.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill description does not clearly warn that it connects to external calendar providers and may transmit account identifiers, event details, attendee information, and scheduling metadata over the network. Without explicit disclosure, users and agents may expose sensitive calendar data without informed consent or proper policy review.

Static analysis

No suspicious patterns detected.