T09 · Insecure Skill Coding Practices
- Location
index.js:51- Finding
Unescaped iCalendar Fields Allow Calendar Content Injection
- Content
View full analysis
Vulnerability Details
File Location:
index.js, lines 51–53
Vulnerability Type: iCalendar content injection caused by missing input validation and escaping
Risk Level: MediumVulnerable Code
js `SUMMARY:${ev.summary}`, ev.description ? `DESCRIPTION:${ev.description}` : null, ev.colorId ? `X-GOOGLE-CALENDAR-COLOR:${ev.colorId}` : null,Technical Analysis
The
summary,description, andcolorIdvalues are inserted directly into the generated iCalendar document. The implementation does not validate their types, reject carriage-return or line-feed characters, or escape iCalendar TEXT metacharacters.Under RFC 5545, TEXT values require escaping for backslashes, line breaks, commas, and semicolons. Because a newline begins a new content line, an attacker-controlled value containing CR/LF characters can terminate the intended property and inject additional iCalendar properties or component delimiters. This can produce arbitrary fields, forged event components, deceptive URLs, attendee entries, or alarm definitions in the generated calendar.
Attack Path
-
An attacker gains control over an event field passed to
run(), such assummaryordescription. -
The attacker supplies a value containing a newline followed by valid iCalendar content, for example:
js { summary: "Meeting\nURL:https://phishing.example\nATTENDEE:mailto:victim@example.com", start: "2026-05-31T09:00:00Z", end: "2026-05-31T10:00:00Z" } -
The skill concatenates this value into the output without escaping it.
-
The generated calendar consequently contains attacker-injected properties:
ics SUMMARY:Meeting URL:https://phishing.example ATTENDEE:mailto:victim@example.com -
A user imports or opens the resulting calendar file in a compatible client.
-
Depending on client behavior, the injected content may appear as trusted event metadata, ...[truncated 704 chars]
-
- Remediation
View remediation
Remediation Suggestions
-
Validate that
eventsis an array and that each accepted property has the expected type before serialization. -
Escape RFC 5545 TEXT values through a dedicated serializer:
js function escapeICSText(value) { return String(value) .replace(/\\/g, '\\\\') .replace(/\r\n|\r|\n/g, '\\n') .replace(/,/g, '\\,') .replace(/;/g, '\\;'); } -
Apply escaping to
summaryanddescriptionbefore adding them to the calendar. -
Treat
colorIdas a constrained token rather than general text. Enforce an explicit allowlist or documented format and reject values containing CR/LF. -
Implement RFC 5545 content-line folding so long values cannot produce invalid output.
-
Reject invalid dates and enforce sensible ordering, including requiring
endto occur afterstart. -
Prefer a well-maintained iCalendar serialization library if dependencies are acceptable.
-
Add tests for
\r,\n,\r\n, backslashes, commas, semicolons, component delimiters, injected properties, and excessively long values.
-
