Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill directly instructs an agent to execute a destructive delete command against Google Calendar without requiring user confirmation, preview of the target event, or safeguards against accidental or malicious invocation. In an agent setting, this creates a real risk of irreversible deletion of calendar data, especially if parameters are inferred incorrectly or supplied by an untrusted prompt/source.
