Back to skill

Security audit

Calendar Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill locally generates calendar files from supplied event data and shows no evidence of hidden access, persistence, exfiltration, or destructive behavior.

Reasonable to install for local .ics generation, but only feed it trusted or sanitized event data until iCalendar escaping and validation are added. Also expect the documented lastDate date-shifting feature not to work as written.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:51
Finding

Unescaped iCalendar Fields Allow Calendar Content Injection

Content
View full analysis

Vulnerability Details

File Location: index.js, lines 51–53
Vulnerability Type: iCalendar content injection caused by missing input validation and escaping
Risk Level: Medium

Vulnerable Code

js
`SUMMARY:${ev.summary}`,
ev.description ? `DESCRIPTION:${ev.description}` : null,
ev.colorId ? `X-GOOGLE-CALENDAR-COLOR:${ev.colorId}` : null,

Technical Analysis

The summary, description, and colorId values are inserted directly into the generated iCalendar document. The implementation does not validate their types, reject carriage-return or line-feed characters, or escape iCalendar TEXT metacharacters.

Under RFC 5545, TEXT values require escaping for backslashes, line breaks, commas, and semicolons. Because a newline begins a new content line, an attacker-controlled value containing CR/LF characters can terminate the intended property and inject additional iCalendar properties or component delimiters. This can produce arbitrary fields, forged event components, deceptive URLs, attendee entries, or alarm definitions in the generated calendar.

Attack Path

  1. An attacker gains control over an event field passed to run(), such as summary or description.

  2. The attacker supplies a value containing a newline followed by valid iCalendar content, for example:

    js
    {
      summary: "Meeting\nURL:https://phishing.example\nATTENDEE:mailto:victim@example.com",
      start: "2026-05-31T09:00:00Z",
      end: "2026-05-31T10:00:00Z"
    }
    
  3. The skill concatenates this value into the output without escaping it.

  4. The generated calendar consequently contains attacker-injected properties:

    ics
    SUMMARY:Meeting
    URL:https://phishing.example
    ATTENDEE:mailto:victim@example.com
    
  5. A user imports or opens the resulting calendar file in a compatible client.

  6. Depending on client behavior, the injected content may appear as trusted event metadata, ...[truncated 704 chars]

Remediation
View remediation

Remediation Suggestions

  1. Validate that events is an array and that each accepted property has the expected type before serialization.

  2. Escape RFC 5545 TEXT values through a dedicated serializer:

    js
    function escapeICSText(value) {
      return String(value)
        .replace(/\\/g, '\\\\')
        .replace(/\r\n|\r|\n/g, '\\n')
        .replace(/,/g, '\\,')
        .replace(/;/g, '\\;');
    }
    
  3. Apply escaping to summary and description before adding them to the calendar.

  4. Treat colorId as a constrained token rather than general text. Enforce an explicit allowlist or documented format and reject values containing CR/LF.

  5. Implement RFC 5545 content-line folding so long values cannot produce invalid output.

  6. Reject invalid dates and enforce sensible ordering, including requiring end to occur after start.

  7. Prefer a well-maintained iCalendar serialization library if dependencies are acceptable.

  8. Add tests for \r, \n, \r\n, backslashes, commas, semicolons, component delimiters, injected properties, and excessively long values.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
3. **Run the skill** – invoke the `run` function exported by `index.js` with the event array and optional `lastDate`.

Static analysis

No suspicious patterns detected.