Back to skill

Security audit

Google 日历基础版

Security checks across malware telemetry and agentic risk

Overview

The skill mostly matches Google Calendar management, but it asks for calendar credentials and mutation authority while giving overly broad triggers and a misleading local-only privacy claim.

Review this skill before installing. Only use it for explicit calendar tasks, verify which Google or CalDAV account it will access, and require confirmation before creating or deleting events. Do not rely on the local-only privacy claim; calendar operations necessarily involve external calendar services.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill claims the FREE version stores all data locally and does not upload to the cloud, but elsewhere it explicitly depends on Google Calendar API and optional CalDAV network access. This mismatch can mislead users into sharing calendar data under a false privacy assumption, weakening informed consent and potentially exposing sensitive scheduling information to external services.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger condition says to use the skill for broad data analysis, report generation, statistics, and visualization needs, which do not match the actual calendar-management functionality. Overbroad routing cues can cause an agent to invoke this skill in unrelated contexts, leading to unintended command execution, calendar modification, or disclosure of calendar contents when a different tool should have been used.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description advertises the skill for project management, task planning, progress tracking, and team collaboration, which are much broader than basic gcalcli calendar operations. This can cause the agent to over-select the skill for common organizational requests, increasing the chance of unnecessary access to calendar data or execution of destructive actions like deletion in contexts where a non-exec or non-calendar tool would be safer.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.