Back to skill

Security audit

calendar

Security checks for vulnerabilities and agentic risk

Overview

This calendar skill is mostly a documentation-only artifact, but it asks for broad read/write/command authority and includes off-purpose instructions that could cause unintended access or calendar changes.

Review this skill before installing. It appears to be a broad, generated calendar guide rather than a tightly scoped integration. Only use it where broad read/write/exec authority is acceptable, and require explicit confirmation before creating, changing, deleting, syncing, or notifying calendar events.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is presented as a calendar tool, but later advertises generic file handling and command execution. That mismatch can cause an agent or user to grant broader trust and permissions than warranted, enabling unintended filesystem or shell actions under the cover of benign scheduling functionality.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The output schema and surrounding documentation describe grading, scoring, and audit-style results unrelated to calendar operations. This creates capability confusion and increases the chance that an agent routes unrelated tasks to this skill or misinterprets outputs, which can hide unsafe behavior behind inconsistent documentation.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The capability list claims review, monitoring, and report-rating features that do not match a calendar skill. Such contradictions are dangerous because they broaden perceived authority and can be used to justify unexpected data access or off-purpose processing.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation guidance is so broad that it could trigger during ordinary project management or collaboration conversations that do not require calendar access. Overbroad triggering raises the risk of unnecessary access to calendar data or accidental execution of create/modify/delete actions when the user intended only general discussion or planning.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The example trigger phrase is common everyday language and may activate the skill in contexts where the user is only discussing plans. In a skill with write capabilities and event-management functions, accidental invocation can lead to unwanted calendar reads or modifications.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill describes create/modify/query/delete operations without a prominent warning or safeguard for destructive actions like deleting or changing events. In calendar contexts, accidental destructive operations can cause missed meetings, lost scheduling data, and unauthorized changes affecting multiple participants.

Static analysis

No suspicious patterns detected.