Back to skill

Security audit

plaud-recordings-to-google-calendar-events

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed workflow for turning Plaud recording commitments into Google Calendar events and a Sheets ledger, with privacy and install-chain cautions but no evidence of hidden or malicious behavior.

Install from the most trusted, reviewable source available, prefer pinned or verified installation paths where possible, and use least-privilege Plaud/Google scopes. Before running it on sensitive recordings, confirm you are comfortable with transcript excerpts and recording links being stored in Google Calendar and Google Sheets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:33
Finding

Unpinned Third-Party Packages Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27, 31, 33–38, 56, 65, 74, 85, 92, and 97–104
Vulnerability Type: Supply-chain exposure caused by mutable, unverified dependencies
Risk Level: Medium

Complete Code Snippet

The primary installation block appears at SKILL.md:33–38:

bash
skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

The same unpinned installation pattern is used for the operational integrations:

```text
npx skills add AgentPMT/agent-skills --skill get-users-current-time-date
npx skills add AgentPMT/agent-skills --skill plaud
npx skills add AgentPMT/agent-skills --skill google-calendar
npx skills add AgentPMT/agent-skills --skill google-sheets

The skill also recommends reinstalling mutable external components:

text
If the current date is more than 7 days after the last updated date, reinstall this skill from skills.sh or ClawHub before relying on endpoints, schemas, setup steps, or examples.

Technical Analysis

The documented commands invoke npx skills without specifying a reviewed version of the skills package. Depending on local npm behavior and cache state, npx can retrieve and execute the current package version from the configured registry.

The AgentPMT/agent-skills source is also referenced without an immutable release tag, commit hash, integrity digest, or signature. Consequently, the code and instructions installed by these commands can change after this skill has been audited. The project contains no lockfile, vendored dependency copy, checksum manifest, or other mechanism that binds installation to reviewed content.

This is an insecure dependency and supply-chain pattern rather than evidence that the current external packages are malicious. Exploitation requires compromise or malicious mod ...[truncated 1909 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the skills CLI to an explicitly reviewed version, for example npx skills@<reviewed-version>, rather than resolving the latest available release.
  2. Pin AgentPMT/agent-skills to an immutable commit hash or cryptographically signed release instead of a mutable repository reference.
  3. Publish and verify integrity hashes or signatures for every installed skill artifact.
  4. Maintain a lockfile or a reviewed, vendored copy of required dependencies so installations are reproducible.
  5. Replace automatic freshness-based reinstall guidance with a controlled update process that reviews changes before deployment.
  6. Run installation in a restricted sandbox without Plaud, Google, AgentPMT, or unrelated local credentials in the environment.
  7. Apply least-privilege OAuth scopes to Plaud, Google Calendar, and Google Sheets integrations, and keep package installation separate from authenticated workflow execution.
  8. Review transitive dependencies and package lifecycle scripts before approving each dependency update.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (16)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill automates reading Plaud transcripts and copying surrounding conversation quotes into Google Calendar descriptions and a Google Sheets ledger, but the description does not prominently warn users about this cross-service propagation of potentially sensitive spoken content. This is dangerous because users may authorize the workflow without understanding that private conversation excerpts and scheduling details will be stored in additional third-party services, increasing privacy, confidentiality, and compliance risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs users to install tooling via npx skills ... without pinning an exact package version or immutable source. That creates a supply-chain risk: a future compromised or malicious package release could be fetched and executed at install time, and the skill content explicitly encourages repeated use of that unpinned mechanism.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This unpinned npx skills invocation relies on the latest available package state at execution time. If the upstream package or dependency chain is hijacked, the user may execute attacker-controlled code during installation or setup of the skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill includes another unpinned package execution path through npx, which exposes users to package substitution or malicious update risk. Because this is instructional content, users may trust and run it verbatim, amplifying the danger of any upstream compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This line repeats the same unpinned npx execution pattern, so the package version and transitive dependency set can change over time without review. That makes the installation path non-deterministic and susceptible to supply-chain attacks.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The npx skills command at this location is not version-pinned, so the code retrieved and executed may differ from what the skill author originally tested. A compromised release or dependency could therefore execute with the user's privileges during setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

By referencing npx skills without a fixed version, the skill creates a live dependency on whatever package version is current when a user runs the command. This increases exposure to registry compromise, maintainer account takeover, or malicious dependency updates.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This installation example uses an unpinned npx package invocation, which can silently pull newer code than intended. In a security-sensitive automation ecosystem, that is a real supply-chain weakness because users are likely to execute the command as written.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill again uses a floating npx install pattern. If the package or any dependency becomes malicious, the installation step can become an initial code-execution vector before the workflow is even used.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This line references npx skills without an immutable version, leaving execution dependent on mutable upstream package state. That is dangerous because setup instructions are high-trust copy-paste surfaces frequently abused in supply-chain compromises.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Another unpinned npx reference appears in the tool links section, repeating the same supply-chain risk across the document. Multiple occurrences increase the chance a user follows at least one unsafe command path.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The command on this line is not pinned and therefore may fetch altered code over time. Because it is in a reference section, users may treat it as canonical and run it without additional scrutiny.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This unversioned npx usage preserves a supply-chain attack surface identical to the earlier findings. A malicious update could transform a benign install helper into arbitrary code execution on user systems.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill continues to expose users to mutable-package execution by recommending npx skills without version pinning. This is a genuine weakness because the command is operational, copy-pasteable, and trust-anchored by the skill documentation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This line repeats the same unpinned install pattern in the AgentPMT reference section, expanding the number of unsafe entry points. The context does not mitigate the issue; reference sections are often where users look for authoritative install commands.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The final npx skills reference is also unpinned, leaving installation behavior dependent on external mutable state. In aggregate with the other occurrences, this indicates a systemic documentation weakness rather than an isolated typo.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.