Back to skill

Security audit

nostrcalendar

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to match its scheduling purpose, but it asks for a Nostr private key and installs unpinned code that can sign and publish events.

Review this before installing if the Nostr identity matters. Use a dedicated key, restrict the runtime environment, avoid unrelated secrets in the same process, pin reviewed dependency versions where possible, and require explicit approval before agents publish availability, send booking requests, or negotiate meetings.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned Third-Party Packages Are Installed and Entrusted with Sensitive Credentials

Content
View full analysis
=0.1.1" ], ``` ### Technical Analysis The project directs the environment to install `nostrcalendar` from an external package registry without an exact version, package hash, or lockfile. Although the project metadata identifies itself as version `0.2.3`, the installation command does not enforce `nostrcalendar==0.2.3`. Consequently, installation may resolve to a different future release. The `nostrkey` dependency uses the open-ended constraint `>=0.1.1`, allowing any subsequent version satisfying that range. The implementation of either dependency is absent from the audited artifact, so its behavior cannot be verified from the supplied source. These packages operate in a sensitive context: the documentation instructs users to provide `NOSTR_NSEC`, a private signing key, and the installed libraries communicate with external Nostr relays. A malicious or compromised permitted release could execute code with the Python process's privileges, read environment variables, forge signed events, and transmit information over the network. This is a supply-chain weakness rather than evidence that the currently published packages are malicious. ### Attack Path 1. An attacker compromises a dependency publisher account, build pipeline, package registry entry, or a future package release permitted by the version constraints. 2. The operator follows the documented setup or the ...[truncated 1405 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example code automatically submits a real booking request by calling create_booking immediately after selecting the first available slot, with no interactive confirmation, dry-run mode, or secondary approval step. In a scheduling skill, this can cause unintended outbound actions, spam booking requests, or accidental calendar changes if reused by an agent without additional safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This example publishes the user's availability to an external Nostr relay without any explicit warning, confirmation, or privacy notice at the point of transmission. Availability and timezone data can reveal working patterns and presence information, and in the Nostr context publication may be broadly discoverable and difficult to retract once shared.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The metadata requires a highly sensitive secret, NOSTR_NSEC, which is the entity's Nostr private key, but it does not include an explicit warning about irreversible account compromise if the key is exposed through logs, prompts, crash reports, or relay-related misuse. In an agent skill context, asking operators to supply a private key materially increases risk because the skill may gain signing authority over identity and communications, making accidental disclosure or unsafe handling a real security issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The availability rule fixes the timezone to America/Vancouver, which imposes a specific locale setting in the skill behavior. Because the file does not present this as user-configurable or justified as region-specific, it can violate the language/locale policy requirement for opt-in or documented constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.