Back to skill

Security audit

Email To Calendar

Security checks for vulnerabilities and agentic risk

Overview

The skill’s core email-to-calendar purpose is coherent, but it tries to add persistent heartbeat behavior that can keep scanning and modifying email after setup.

Review this before installing. It is not showing remote code execution or data exfiltration, but it can read Gmail, modify Gmail labels, manage Calendar events, write local tracking logs, and add recurring instructions to shared heartbeat memory. Only install if you explicitly want recurring inbox scanning and automatic archiving/mark-read behavior, and check the config plus HEARTBEAT.md for a way to disable or remove those behaviors.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Error
Location
BOOT.md:34
Finding

Persistent Injection of Skill-Controlled Rules into Shared Agent Heartbeat Memory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (41)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 13)May include surrounding context.

md
### Fixed
- **Shell injection / quoting in `event_tracking.py`**: The orphan-cleanup path
  used `subprocess.run(..., shell=True)` with an interpolated event ID — the last
  instance of the shell-quoting bug class fixed across the other scripts in
  v1.13.0/v1.13.1. Converted to safe list-form arguments. Also clears the
  `code-execution` finding in ClawHub's static security scan.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description centers on converting emails into Google Calendar events and managing those events. This code chunk instead focuses on finding unread Google calendar-notification emails and disposing of them if their subjects match reply/update/cancellation patterns. That is a Gmail message-cleanup/disposition function, not event extraction or calendar creation/update. While mail disposition is mentioned in the description as a supporting feature, in this chunk it is the sole behavior and it operates on calendar reply notifications specifically, which is materially different from the declared primary purpose. Therefore this chunk does not accurately represent the described functionality and should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a full email-to-calendar automation skill, but the actual code shown is only a test runner script. Its primary purpose is executing Python unittests, which is unrelated to scanning Gmail, extracting event data, or managing Google Calendar. This is a material mismatch in behavior and purpose, not merely an omitted implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a full-featured email-to-calendar automation skill. However, the provided code chunk is only an empty Python package initializer for tests with a comment. It does not implement any of the described capabilities, nor does it access the claimed resources. Based on this code chunk alone, the actual behavior is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on a full email-to-calendar skill integrating with Gmail and Google Calendar. The actual code provided does not implement that workflow; it is only a test suite for a local changelog utility. While some tested concepts loosely align with a described supporting feature (24-hour undo and local state tracking), the chunk’s primary purpose is unrelated test logic around local JSON change records. There is no evidence of Gmail access, calendar management, email parsing, reminder sending, or mail labeling/archiving in this code. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code chunk does not implement the declared skill functionality. It is a standalone test module validating helper functions in utils.common. The functions under test are generic formatting/ID/time helpers and are only indirectly related at best. There is no evidence of Gmail reading, Google Calendar management, gog CLI usage, reminder handling, processed-mail actions, undo logic, or any email/calendar workflow. Because the actual code's primary purpose is materially different from the declared description, this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This code chunk is not malicious or performing undeclared sensitive actions; however, it does not implement the declared end-user skill behavior. Instead, it is a narrow internal test module for parsing dates and times. Date/time parsing could be a supporting implementation detail for an email-to-calendar skill, but the actual chunk’s primary purpose is testing that helper logic, not scanning Gmail or managing calendar events. Therefore, the supplied code chunk does not accurately represent the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description centers on a fully featured Gmail-to-Google-Calendar automation workflow. The provided code chunk does not implement any of those capabilities. Instead, it is strictly a test module for JSON file persistence helpers, using temporary directories and local files. While local JSON storage could be a supporting detail of the declared skill, this specific chunk’s actual behavior is only unit testing that storage layer and shows none of the core declared functionality or resource access (Gmail, Calendar, gog CLI, reminders, labeling, etc.). Therefore the code chunk does not accurately represent the declared purpose and should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/gog-commands.md (reported line 96)May include surrounding context.

md
| Thursday | TH |
| Friday | FR |
| Saturday | SA |
| Sunday | SU |

## Key Flags

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · BOOT.md (reported line 13)May include surrounding context.

md
Verify the agent can:
- Read emails (list unread, get message body)
- Create calendar events
- Update/delete calendar events

If any capability is missing, inform the user:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The bootstrap instructs the agent to read and potentially modify a global HEARTBEAT.md outside the skill's own directory, creating persistent behavioral changes beyond the immediate user request. This expands the skill's influence into shared agent state and can cause ongoing email/calendar processing behavior to persist across sessions without clear, per-use user consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

These instructions push persistent email-scanning and invite-handling logic into the agent heartbeat, effectively converting an on-demand skill into a background behavioral modification. That kind of scope expansion is risky because it can lead to continued mailbox monitoring, event creation prompts, and state changes unrelated to the user's immediate invocation of the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The heartbeat content explicitly directs the agent to 'Log all scanning activity silently for audit trail,' which creates undisclosed monitoring and retention of user email-processing activity. Silent logging is dangerous because users may not realize their message metadata or processing history is being stored persistently, raising privacy and consent concerns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The self-check executes process_calendar_replies.sh during bootstrap, which performs email-processing side effects rather than only validating setup. Running mutation-capable scripts as part of initialization can archive or alter emails without an explicit user action tied to that specific change.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documented defaults indicate processed emails may be marked read and archived automatically, but BOOT.md does not prominently surface these mailbox-changing behaviors as risky defaults. Automatic disposition of emails can hide messages from the inbox and interfere with the user's normal review workflow if enabled without clear consent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · CHANGELOG.md (reported line 274)May include surrounding context.

md
### Fixed
- Stale forward handling: Old emails forwarded today are now properly processed.
- Orphaned events: Events deleted in Google Calendar are now automatically removed from tracking.

## [1.5.0] - 2026-02-02

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · CHANGELOG.md (reported line 294)May include surrounding context.

md
### Fixed
- Stale forward handling: Old emails forwarded today are now properly processed.
- Orphaned events: Events deleted in Google Calendar are now automatically removed from tracking.

## [1.5.0] - 2026-02-02

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · CHANGELOG.md (reported line 293)May include surrounding context.

md
## [1.4.0] - 2026-02-02

### Added
- **Selective Selection**: Users can now cherry-pick events by number (e.g., '1, 2, 3'), 'all', or 'none' instead of binary yes/no confirmation
- **Self-Healing Tracking**: When updating an event that was deleted externally (404/410), automatically removes stale tracking entry and creates a new event

### Removed

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SETUP.md (reported line 30)May include surrounding context.

md
5. Whole-day events: Timed (9 AM - 5 PM)
6. Multi-day events: Daily recurring
7. Ignore patterns: (none)
8. Auto-create patterns: (none)
9. Email handling: Mark as read and archive (recommended)
   Also auto-process calendar replies? (Y/n)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The setup flow presents mailbox-modifying behavior as a recommended default and encourages accepting all defaults with a single Enter press, but it does not clearly warn that processed emails will be marked read, archived, and calendar replies may be auto-processed. In a skill that reads a live inbox, this can cause unintended integrity changes to the user's mailbox and hide messages before the user understands the consequences.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SETUP.md (reported line 232)May include surrounding context.

If you prefer to skip the interactive setup:

bash
mkdir -p ~/.config/email-to-calendar
cat > ~/.config/email-to-calendar/config.json << 'EOF'
{
  "provider": "gog",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The prerequisites and surrounding documentation describe broad inbox-reading and calendar-management capabilities, including create, update, and delete actions, without a prominent privacy and integrity warning. Because this skill operates on sensitive email contents and can alter calendar data, insufficient disclosure increases the risk of users granting powerful access without informed consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill clearly instructs use of shell scripts, local file reads/writes, and stateful logging, but it declares no explicit tool permissions or allowed-tools scope. That mismatch can cause the agent to run with broader-than-expected capabilities or without transparent least-privilege boundaries, which is a real security governance issue for a skill that reads Gmail, modifies Calendar, sends email, and writes local state.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs persistent use of MEMORY.md plus detailed local logs, pending invite tracking, and changelog data derived from email content. Because emails can contain sensitive personal, corporate, scheduling, and attendee information, retaining this material in natural-language memory and JSON logs increases privacy exposure, cross-session data leakage risk, and the blast radius of local compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guidance tells the agent to delete or modify calendar events when cancellation language is detected, but it does not require an explicit confirmation step immediately before taking that destructive action. Because email text can be ambiguous, spoofed, or misparsed, this can lead to unauthorized deletion or corruption of legitimate calendar entries, which is especially risky in a skill that automates Gmail-to-Calendar workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.