Back to skill

Security audit

钉钉日历专业版

Security checks across malware telemetry and agentic risk

Overview

The skill is a DingTalk calendar helper, but it grants broad file and command authority and can automate bulk calendar changes without clear confirmation boundaries.

Review this before installing in an enterprise agent. Limit use to DingTalk calendar tasks, require confirmation before creating, updating, canceling, or bulk-inviting attendees, restrict command execution to mcporter calendar commands, and avoid configuring webhooks or shared credentials unless their destination and access controls are trusted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill claims to be a DingTalk calendar tool, but later advertises broad file handling, API integration, search, and command execution capabilities unrelated to that narrow purpose. This scope expansion increases the chance an agent will use powerful local or system actions under the guise of a calendar task, creating an unnecessary path to arbitrary file or command access.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Documenting file read/write capability for a calendar-management skill violates least privilege because local file modification is not clearly necessary for the stated function. An agent may infer permission to access or alter local data, leading to unintended disclosure or corruption of user files.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Advertising system command execution for a calendar skill is broader than justified and can enable arbitrary shell activity if an agent follows the documentation too literally. In an agent context, this creates a dangerous bridge from benign scheduling requests to local command execution, with risk of data exfiltration, persistence, or destructive actions.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill whenever efficiency, automation, batch processing, or workflow optimization is needed, which is far broader than DingTalk calendar management. Such vague triggering can cause an agent to apply this skill in unrelated contexts and invoke unnecessary high-privilege tools.

Vague Triggers

Medium
Confidence
86% confidence
Finding
Stating that users can trigger the skill through natural-language instructions without clear boundaries encourages over-broad autonomous interpretation. In combination with exec/read/glob/grep tools, this can lead the agent to perform actions beyond what the user reasonably intended.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill supports automatic calendar creation and meeting invitations, including batch operations, but does not require confirmation before making potentially disruptive changes. This can result in accidental mass scheduling, attendee spam, or unauthorized modifications to calendars at enterprise scale.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documented webhook notification feature can send calendar or operational data to external endpoints, but there is no privacy or data-minimization warning. This creates a risk of transmitting sensitive scheduling metadata, attendee details, or audit information to untrusted destinations.

Missing User Warnings

Low
Confidence
81% confidence
Finding
If the skill is interpreted as supporting file write operations, it does not warn users that local data may be modified. Lack of notice increases the chance of unintended overwrites or changes to user-controlled files.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.