Back to skill

Security audit

calendar-sync-tool

Security checks across malware telemetry and agentic risk

Overview

This calendar skill is not clearly malicious, but it asks for broader command and file capabilities than its calendar purpose explains.

Review this skill before installing. It may be usable for Feishu/Lark calendar work, but only grant it access in an environment where shell execution and local file search are acceptable, and avoid using broad calendar credentials unless you are comfortable with event details being read or synced through Feishu/Lark APIs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a Feishu/Lark calendar manager, but later documentation expands its scope to file handling, API integration, information retrieval, and command execution. This capability mismatch can mislead users and orchestrators into granting or invoking broader operations than expected, increasing the risk of unintended file access or shell execution under a benign-looking calendar label.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The manifest grants the skill generic `exec` capability even though its stated purpose is limited to calendar management. Unnecessary shell execution materially expands the attack surface because a compromised or poorly specified workflow could run arbitrary commands, access local data, or pivot beyond the intended calendar scope.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation condition says to use the skill whenever the user needs calendar-sync-tool-related functionality, which is overly broad and self-referential. Loose invocation boundaries can cause the agent to trigger the skill in inappropriate contexts, potentially exposing calendar data or enabling connected tools without clear user intent.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill describes reading, searching, and syncing calendar data but does not clearly disclose that this may involve transmitting sensitive scheduling information to external Feishu/Lark services. Lack of clear disclosure can undermine informed consent and create privacy and data-handling risks, especially for enterprise calendars containing confidential meetings or participant details.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.