Back to skill

Security audit

gcal-pro - Google Calendar

Security checks for vulnerabilities and agentic risk

Overview

This is a real Google Calendar skill, but it needs review because its code can change or delete calendar events even when confirmation was not actually provided.

Review before installing. Use this only if you are comfortable granting Google Calendar access, and avoid Pro write operations until confirmation enforcement is fixed. Keep client_secret.json and token.json private, do not print or share them, and consider installing dependencies in an isolated environment with reviewed or pinned versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gcal_core.py:491
Finding

Calendar mutations execute without enforced user confirmation

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/gcal_license.py:20
Finding

Unnecessary hostname and username collection creates a persistent machine fingerprint

Content
View full analysis
str: """Generate a machine-specific identifier.""" # Combine hostname and username for basic machine ID import socket hostname = socket.gethostname() username = os.environ.get("USERNAME") or os.environ.get("USER") or "unknown" raw = f"{hostname}:{username}" return hashlib.sha256(raw.encode()).hexdigest()[:16] ``` ```python # Create license file license_data = { "key": key.upper().strip(), "tier": "pro", "valid": True, "activated_at": datetime.utcnow().isoformat(), "machine_id": get_machine_id() } ``` ### Technical Analysis License activation reads the local hostname and operating-system username, combines them, computes a truncated SHA-256 digest, and stores the resulting stable identifier in `~/.config/gcal-pro/license.json`. This qualifies as limited environment reconnaissance because the skill inspects host and account identity data unrelated to Google Calendar functionality. The collection also exceeds the minimum needs of the current license implementation: `machine_id` is written but never checked by `validate_license_key()`, `get_license_info()`, or `is_pro()`. Hashing does not make the identifier anonymous. Hostnames and usernames often have low entropy and can be guessed or correlated, while truncating the digest to 16 hexadecimal characters does not prevent dictionary testing. The setup and privacy documentation do not disclose this collection. No code was found that transmits the hostname, username, or machine identifier to a remote endpoint. The current impact is therefore local collection and persistent fingerprinting, not confirmed network exfiltration. ### Attack Path 1. A user runs license activation: ```b ...[truncated 1065 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:2
Finding

Open-ended dependency versions permit unreviewed supply-chain changes

Content
View full analysis
=2.23.0 google-auth-oauthlib>=1.1.0 google-auth-httplib2>=0.1.1 google-api-python-client>=2.100.0 pytz>=2023.3 python-dateutil>=2.8.2 ``` The installation documentation directs users to execute: ```text pip install -r requirements.txt ``` ### Technical Analysis Every dependency uses an open-ended minimum version constraint. Installation can therefore resolve to any later release available from the configured Python package index. There is no lock file, upper bound, hash verification, or reproducible dependency set. The package names are consistent with the declared Google Calendar functionality, and no currently listed package was established to be malicious during this static audit. The vulnerability is that future installation behavior can change after review without any modification to the skill package. This is especially relevant because the dependencies run in a process that reads OAuth client credentials and refresh tokens and accesses private calendar data. ### Attack Path 1. A user follows the installation guide and runs `pip install -r requirements.txt`. 2. `pip` resolves the newest versions satisfying the `>=` constraints at installation time. 3. A compromised upstream release, package-index compromise, malicious mirror, or unexpectedly incompatible future release is selected. 4. Third-party code executes during installation or when imported by the skill. 5. That code runs with the user's local process privileges and may access files and data available to the calendar process. This is a conditional supply-chain path; the audit did not identify a presently malicious dependency. ### Impact Assessment A compromised or unsafe resolved dependency could potentially access: - `~/.config/gcal-pro/client_secret.json` - `~/.config/gcal-pro/token.json`, ...[truncated 456 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (53)

Credential Access

High
Category
Privilege Escalation
Confidence
78% confidence
Finding

The README states that token.json stores the user's access token but does not warn that possession of this file may allow calendar access. In the context of a skill handling personal scheduling data, failing to treat persisted tokens as sensitive secrets can lead to accidental exposure through weak file permissions, backups, or shared systems.

Content

Scanner excerpt · README.md (reported line 114)May include surrounding context.

md
| File | Purpose |
|------|---------|
| `client_secret.json` | OAuth app credentials (you provide) |
| `token.json` | Your access token (auto-generated) |
| `license.json` | Pro license (if purchased) |

## Clawdbot Integration

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented behavior says this is a Google Calendar skill, but the detected implementation reportedly performs licensing and machine-identification functions while lacking actual calendar functionality. That mismatch is a strong trust-boundary violation: users or calling agents may grant calendar-related privileges while the skill instead handles local identifiers and license state, suggesting hidden or undeclared behavior.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
74% confidence
Finding

The documented file layout stores OAuth client credentials, access tokens, and license data together under a predictable path in the user's home directory. In an agent environment that also uses file_read/file_write capabilities, predictable plaintext storage increases the risk of accidental disclosure, overbroad access by other skills, or token theft if local files are exposed.

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

text
~/.config/gcal-pro/
├── client_secret.json   # OAuth app credentials (user provides)
├── token.json           # User's access token (auto-generated)
└── license.json         # Pro license (if purchased)

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The documentation explicitly indicates persistent local storage of a user's access token in token.json. Access tokens can authorize calendar access without re-prompting the user, so theft of this file could enable unauthorized reading or modification of calendar data depending on granted scopes.

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

text
~/.config/gcal-pro/
├── client_secret.json   # OAuth app credentials (user provides)
├── token.json           # User's access token (auto-generated)
└── license.json         # Pro license (if purchased)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README-INSTALL.txt (reported line 32)May include surrounding context.

text
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 40)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 113)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 131)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 4)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 123)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 149)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 162)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 168)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 177)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 182)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 207)May include surrounding context.

md
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gcal_auth.py (reported line 20)May include surrounding context.

python
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gcal_auth.py (reported line 39)May include surrounding context.

python
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gcal_auth.py (reported line 78)May include surrounding context.

python
# Google Cloud Project Setup Guide

## Overview
This guide walks you through creating a Google Cloud project, enabling the Calendar API, and configuring OAuth 2.0 to get your `client_secret.json` file.

**Time required:** ~15 minutes  
**Prerequisites:** Google account

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This section not only moves a sensitive credential file into a persistent config directory but also immediately instructs the user to print its contents for verification. The dangerous part is the exposure path, which can leak OAuth client secrets through terminal history, logs, screenshots, or recorded sessions.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 137)May include surrounding context.

md
New-Item -ItemType Directory -Force -Path "$env:USERPROFILE\.config\gcal-pro"

# Move the downloaded file (adjust source path as needed)
Move-Item "$env:USERPROFILE\Downloads\client_secret*.json" "$env:USERPROFILE\.config\gcal-pro\client_secret.json"

# Verify
Get-Content "$env:USERPROFILE\.config\gcal-pro\client_secret.json" | Select-Object -First 3

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Get-Content ... | Select-Object -First 3 deliberately reveals the beginning of the secret-bearing OAuth credentials file in the terminal. That creates an unnecessary credential exposure channel and is inconsistent with the document's later warning not to share these files.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 140)May include surrounding context.

Move-Item "$env:USERPROFILE\Downloads\client_secret*.json" "$env:USERPROFILE.config\gcal-pro\client_secret.json"

Verify

Get-Content "$env:USERPROFILE.config\gcal-pro\client_secret.json" | Select-Object -First 3

text

**macOS/Linux:**

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

head -3 ~/.config/gcal-pro/client_secret.json exposes the contents of a sensitive OAuth credential file to the terminal. This creates avoidable leakage risk through shell history, shared terminals, support captures, and screenshots.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 152)May include surrounding context.

mv ~/Downloads/client_secret*.json ~/.config/gcal-pro/client_secret.json

Verify

head -3 ~/.config/gcal-pro/client_secret.json

text

---

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/GOOGLE_CLOUD_SETUP.md (reported line 178)May include surrounding context.

⚠️ NEVER commit these files to git:

  • client_secret.json — Your app's credentials
  • token.json — User's access tokens

Add to .gitignore:

text

Static analysis

No suspicious patterns detected.