Back to skill

Security audit

Fcalendar Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent calendar helper, but it can automatically trigger broad shell-based package checks and unpinned PyPI installation for common time mentions.

Review before installing. The calendar functionality is understandable, but only use it in an environment where running pip installs and Python imports is acceptable. Prefer a pinned, reviewed fcalendar version in a virtual environment, and avoid auto-triggering this skill for casual mentions of dates or weekdays.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:29
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 29–35
Vulnerability Type: Unpinned dependency installation from an external package repository
Risk Level: High

Vulnerable Code

bash
python3 -m pip install fcalendar 
bash
python3 -m venv venv
source venv/bin/activate  # On Windows: venv\Scripts\activate
python3 -m pip install fcalendar

Technical Analysis

The skill instructs the agent to install the latest available fcalendar release from PyPI without specifying an exact version or verifying a cryptographic hash. Consequently, the dependency installed during future skill executions may differ from the package version available when this skill was audited.

A virtual environment limits dependency conflicts but does not establish package integrity or prevent malicious installation and runtime code from executing. The external PyPI package and linked source repository are not included in this project artifact and therefore were not part of the audited code.

This creates a supply-chain exposure: compromise of the package, its maintainer account, or its release process could cause arbitrary Python code to execute when the package is installed or invoked.

Attack Path

  1. An attacker compromises the upstream fcalendar package, its publishing credentials, or its release pipeline.
  2. The attacker publishes a malicious package version to the expected PyPI project.
  3. A user submits a date- or time-related request that triggers this skill.
  4. The skill's package check fails because fcalendar is not installed.
  5. The agent runs python3 -m pip install fcalendar.
  6. Pip retrieves the current uncontrolled release and installs it.
  7. Malicious installation or runtime code executes with the operating-system privileges of the agent process.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the agent's account. Depending on that account's permissions and environment, the maliciou ...[truncated 396 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an exact, reviewed version, for example:
    bash
    python3 -m pip install "fcalendar==<audited-version>"
    
  2. Maintain a lock or requirements file containing cryptographic hashes and install with hash enforcement:
    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Audit the pinned source distribution and wheel before approving them.
  4. Prefer bundling a reviewed implementation in the skill artifact when licensing and maintenance requirements permit.
  5. Continue using an isolated virtual environment, but do not treat isolation as a substitute for provenance and integrity verification.
  6. Restrict the installation and runtime environment using least privilege, outbound network controls, and filesystem access controls.
  7. Define a controlled update process in which new dependency versions are reviewed and their hashes are updated explicitly.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

Package Verification Executes an Unverified Import

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–24
Vulnerability Type: Unsafe package-presence check through executable Python import
Risk Level: Medium

Vulnerable Code

bash
python3 -c "import fcalendar; print('fcalendar installed, version:', fcalendar.__version__)"

Technical Analysis

The prerequisite check imports fcalendar before establishing the module's origin or integrity. Importing a Python package is an executable operation: Python runs the package's initialization code during import.

Python module resolution can include the current working directory and other environment-controlled entries in sys.path. If a malicious actor can place a file named fcalendar.py or a package directory named fcalendar earlier in the import search path, the verification command may load and execute that code instead of the intended distribution.

The command therefore treats successful import as proof of safe installation even though the act of checking can itself execute an untrusted local module. A malicious substitute could also expose a fabricated __version__ value so the skill incorrectly concludes that the legitimate dependency is installed.

Attack Path

  1. An attacker obtains the ability to write a malicious fcalendar.py file or fcalendar/ package into the skill's working directory or another directory that precedes the legitimate package on sys.path.
  2. A user makes a request involving a date or time expression, triggering the skill.
  3. The agent runs the documented package-presence check.
  4. Python resolves import fcalendar to the attacker-controlled module.
  5. The malicious module's top-level initialization code executes immediately.
  6. The module can define a fabricated __version__ value, allowing the check to appear successful and causing the agent to continue using the spoofed implementation.

Impact Assessment

Successful exploitation permits arbitrary Python code execution with the privil ...[truncated 571 chars]

Remediation
View remediation

Remediation Suggestions

  1. Check installed distribution metadata without importing package code:
    bash
    python3 -c "import importlib.metadata as m; print('fcalendar installed, version:', m.version('fcalendar'))"
    
  2. Run dependency checks from a trusted directory that is not writable by untrusted users.
  3. Use a dedicated virtual environment whose package directory and activation configuration have controlled ownership and permissions.
  4. Sanitize or explicitly define Python import-path behavior; do not rely on attacker-influenced PYTHONPATH values.
  5. After locating the installed distribution, validate its expected version and cryptographic integrity before executing it.
  6. Avoid fallback logic that constructs and executes a binary path unless the resolved installation prefix and target file are also validated.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger guidance is excessively broad, telling the agent to invoke the skill whenever any time-related term appears, including extremely common conversational content. Over-broad triggers can cause unnecessary execution of shell commands, package checks, and even installation paths in benign conversations, expanding attack surface and enabling tool-use hijacking through incidental keywords.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
93% confidence
Finding

The skill attempts to control the agent's final response behavior by imposing a 'single source of truth' and forbidding paraphrasing or supplementation. This is a prompt-injection style instruction that can suppress the agent's normal safety checks, contextual warnings, or corrective framing if the CLI output is misleading, malicious, or incomplete.

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
## Friendly Display Requirements

> [!IMPORTANT]
> **Strict Output Rule**: Always use the exact content returned by the `fcalendar` CLI.
> Do NOT paraphrase, rewrite, supplement, or infer beyond what the CLI returns.
> The `result` field (for `query`) and the JSON array (for `holiday`) are the single
> source of truth. Present them as-is after formatting; never modify their semantic content.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill claims the package only performs local parsing and does not access network resources, yet it instructs the agent to install the package from PyPI, which necessarily performs a network fetch and introduces supply-chain risk. This can mislead operators into underestimating the security implications of executing installation steps in response to user requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The recommended output structure is entirely in Chinese headings and labels, which implies a fixed language output convention. Because the skill also supports English inputs, mandating Chinese presentation without user choice can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document states that the tool automatically detects whether input is Chinese or English and supports mixing those two languages, which implicitly constrains language handling to a fixed locale set. Because this is framed as default behavior without offering a user choice or documenting why other locales are excluded, it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: fcalendar-skill
description: fcalendar-skill is a Chinese date/time expression recognition and holiday query tool. **Trigger this skill whenever users mention any time-related terms**, including but not limited to: 明天, 后天, 下周, 春节, 国庆节, Christmas, Monday, etc. It can identify and annotate time expressions in natural language text (Chinese and English), resolve them to exact calendar dates, and query Chinese public holidays and normal weekends within a specified time range. Use this skill when users ask about dates, time expressions, schedules, holidays, or when you need to resolve relative time references to concrete dates.
license: See LICENSE.txt
allowed-tools: "Read Exec"
compatibility: "Requires Python 3.7+. Supports Linux, macOS, and Windows systems."

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The field description states the name field will contain the holiday name or "周末" for weekends, and the examples consistently use Chinese output names. Because this markdown does not mention any language option or opt-in for localized output, it implies a fixed locale behavior that may conflict with a language-choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.