Back to skill

Security audit

calendar-sync-tool

Security checks for vulnerabilities and agentic risk

Overview

This calendar skill is not malicious on inspection, but it asks for broad local file and command-execution authority that is not clearly scoped to calendar use.

Review before installing. Use this only if you are comfortable granting the agent local file read/search and shell execution capabilities for a calendar workflow. Prefer a version that uses narrowly scoped Lark calendar API permissions, avoids generic exec access, and requires explicit confirmation for any file or command action.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:19
Finding

Excessive Agent Tool Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19–23
Vulnerability Type: Excessive tool permissions violating least privilege
Risk Level: Medium

Vulnerable Code

yaml
tools:
  - read
  - exec
  - glob
  - grep

Related capability claims appear at lines 181–185:

markdown
- **自动化执行**: 管理飞书Lark日历,列出/搜索/查日程/同步事件,办公协同。Manage Feishu (Lark) calendar
- **文件处理**: 支持多种文件格式的读取、解析和写入操作
- **API集成**: 通过标准化接口调用外部服务并处理响应
- **命令执行**: 在安全沙箱中执行系统命令并收集结果
- **信息检索**: 快速搜索和过滤目标数据

Technical Analysis

The Skill requests general-purpose local file-reading, filesystem-search, and command-execution capabilities. These permissions are not necessary for its stated purpose of listing, searching, checking, and synchronizing Lark calendar events. Calendar management should instead use a narrowly scoped calendar API integration.

Granting read, glob, and grep expands the accessible scope to local files, while exec introduces a general command-execution channel. Although the reviewed file contains no direct malicious command or demonstrated exploit payload, this permission set breaks the principle of least privilege and increases the consequences of malicious or attacker-controlled input processed during Skill use.

The project contains only SKILL.md and does not define path restrictions, command allowlists, argument validation, user-confirmation requirements, or a constrained Lark calendar tool.

Attack Path

  1. An Agent loads the Skill and grants the declared read, glob, grep, and exec tools.
  2. The Skill processes attacker-controlled or otherwise untrusted calendar content or user input.
  3. Crafted input attempts to induce the Agent to perform operations unrelated to calendar management.
  4. The broadly granted tools may allow the Agent to discover and read local files or execute local commands.
  5. The resulting access is limited by the Agent sandbox and operating-sys ...[truncated 593 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove exec, read, glob, and grep unless each capability has a documented and unavoidable calendar-specific requirement.
  2. Replace general tools with a narrowly scoped Lark calendar API tool that permits only required operations and approved Lark HTTPS endpoints.
  3. Use minimally scoped Lark credentials and restrict them to the required calendars and event operations.
  4. If local file access is indispensable, enforce an explicit path allowlist, reject traversal and symbolic-link escapes, and prohibit access to secrets, environment files, and credentials.
  5. If command execution is indispensable, use fixed executable and argument allowlists, avoid shell interpretation, apply strict time and resource limits, and require explicit user confirmation.
  6. Treat calendar fields and user-provided content as untrusted data rather than executable Agent instructions.
  7. Document the exact required permissions and add tests verifying that unrelated filesystem and command operations are denied.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The invocation guidance says to use the skill whenever the user needs anything related to calendar-sync-tool, which is overly broad and lacks boundaries for sensitive actions. In a skill that also exposes exec and broad automation language, vague trigger criteria can cause over-invocation, unnecessary privilege use, and unintended execution in contexts where a narrower, safer tool should be chosen.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises automation features and includes tools such as exec, yet the markdown lacks a clear user-facing warning that command execution and potentially file-modifying behavior may occur. This is dangerous because users may invoke what appears to be a simple calendar skill without understanding that it can run system commands, which materially changes the risk profile and can enable harmful actions if misused or compromised.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a Feishu calendar tool, but later documents broad file handling, API integration, and system command execution capabilities unrelated to that purpose. This scope drift can mislead users and orchestrators into granting or invoking much more powerful behaviors than expected, increasing the risk of unauthorized file access, shell execution, or lateral misuse under a benign-looking calendar label.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The '专业版增值服务' section lists capabilities like bulk message sending, message templates, delivery callbacks, and communication record archiving, which contradict the rest of the document presenting this as a calendar tool and '不支持' for out-of-scope usage. This appears to be copied documentation that conflicts with the stated intent of the skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The FAQ explicitly states '目前日历工具不支持设置事件提醒功能,' but nearby sections present expansive generic automation/API/command capabilities that make the documented functional boundary unclear. This creates intent confusion in the documentation about what the tool actually supports.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.