Back to skill

Security audit

Calendar Query

Security checks across malware telemetry and agentic risk

Overview

This skill is a read-only calendar helper, but it would use an already-authenticated account to access named work and personal calendars with broad activation wording and limited consent guidance.

Install only if you are authorized to let the agent read Matt's Flowcode and personal calendars through the local gog authentication. Use narrow date ranges and specify which calendar should be checked; avoid using this in shared environments or where personal calendar details should not be surfaced.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill is triggered by broad terms like schedules, events, availability, or reminders, which can match many ordinary user requests without clearly signaling that authenticated calendar data will be accessed. In this context, that creates a real risk of over-collection or unintended disclosure of sensitive work and personal scheduling information when the user did not explicitly request calendar access.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to read authenticated work and personal calendars but provides no requirement to warn the user that private calendar contents will be accessed. Because the CLI is already authenticated, the agent could retrieve sensitive events, titles, travel, or personal commitments without meaningful transparency or consent, increasing privacy and data-handling risk.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The instructions require prioritizing the work calendar and including personal calendar context by default, even when the user may only be asking about one context. Default inclusion of personal-calendar data without opt-in materially increases the chance of exposing unrelated private information and makes the skill more dangerous because it combines multiple sensitive sources automatically.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.