Back to skill

Security audit

Flow State Monitoring

Security checks for vulnerabilities and agentic risk

Overview

The skill is not deceptive, but it can autonomously create Google Calendar availability events based on vague focus signals, so users should review it carefully before installing.

Install only if you are comfortable with the skill using your configured gog/Google Workspace access to create calendar busy events automatically. Prefer adding explicit consent, a defined event duration, cooldowns, logging, and an easy way to delete events it creates.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest promises a skill that monitors focus and mutes interruptions, but the implementation performs Google Calendar modifications in Google Workspace. This scope mismatch is dangerous because users or orchestrators may grant or trigger the skill under narrower assumptions, while it actually changes external account data and availability signaling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill performs Google Workspace/Calendar operations that go beyond the narrowly described function of monitoring focus and muting interruptions. This creates a permission and expectation gap: a user may approve a passive monitoring skill without realizing it can write to external systems, enabling unintended modifications to calendars and status.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill autonomously modifies external workspace data without an explicit warning that it will create Google Calendar events and affect visible availability/state. This is dangerous because it can alter a user's professional signaling and scheduling records without informed consent, potentially affecting coworkers, automated scheduling tools, and audit trails.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation condition, 'telemetry from local sensors indicates deep focus,' is vague and broad, leaving substantial room for misclassification and autonomous triggering. In this context, that ambiguity is more dangerous because it directly drives external calendar/status changes, so normal activity could be incorrectly interpreted as 'Deep Work' and cause unintended blocking behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.