Back to skill

Security audit

Quick Google Calendar Command Line Interface

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent Google Calendar purpose, but it gives agents unsafe command patterns and allows calendar deletes or edits without a final confirmation.

Install only if you are comfortable letting the agent use authenticated gcalcli to read, create, edit, and delete your Google Calendar events. Before use, consider changing the policy to require confirmation for all deletes and edits, use gcalcli init instead of putting OAuth secrets on a command line, pin the gcalcli version, and ensure commands are executed with safely separated arguments rather than shell-interpolated strings.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:131
Finding

Shell Command Injection Through User-Controlled Calendar Values

Content
View full analysis
" add --noprompt --title "" --when "<Start>" --duration <minutes> gcalcli --nocolor --calendar "<Cal>" add --noprompt --allday --title "<Title>" --when "<Date>" ``` ```bash echo 'BEGIN:VCALENDAR VERSION:2.0 BEGIN:VEVENT DTSTART;VALUE=DATE:20260308 SUMMARY:Event Title RRULE:FREQ=YEARLY TRANSP:TRANSPARENT END:VEVENT END:VCALENDAR' | gcalcli import --calendar "<Cal>" ``` ```bash gcalcli --nocolor delete --iamaexpert "<query>" <start> <end> ``` ### Technical Analysis The Skill instructs the agent to interpolate conversationally supplied calendar names, event titles, dates, times, durations, and search queries into shell command strings. It does not require argument-array execution, escaping, validation, or another mechanism that prevents shell interpretation. Double quotes do not neutralize all shell syntax. Command substitutions such as `$(command)` and backticks can still execute inside double-quoted arguments. A quotation mark may also terminate the expected argument and introduce shell operators. In the ICS example, event data is placed inside a single-quoted `echo` operand; an apostrophe in generated content can terminate that operand and alter the resulting command. The issue applies when an execution environment passes the constructed command through a shell. If the execution tool uses a direct process API with separately encoded arguments, shell injection would be prevented, but the Skill does not mandate that safer execution model. ### Attack Path 1. An attacker causes the user or agent to process a crafted calendar name, event title, or deletion query. 2. The value includes shell metacharacters or command substitution, such as `$(attacker-command)`. 3. The agent substitutes the value into one of the documented com ...[truncated 713 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:19
Finding

OAuth Client Secret Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:14
Finding

Unpinned Third-Party Package Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
96% confidence
Finding

The documented policy to skip confirmation for unambiguous destructive actions is a real autonomy risk. In a calendar-management skill, deletion and edits can have meaningful real-world consequences, and relying on the agent's own ambiguity judgment creates a failure mode where one misinterpreted natural-language request results in unauthorized or unintended destructive changes.

Content

Scanner excerpt · README.md (reported line 44)May include surrounding context.

md
**This skill intentionally skips user confirmation for unambiguous destructive actions (delete/edit).** This is a deliberate UX decision, not an oversight. Here's why and how it's kept safe:

### Why skip confirmation?

This skill is designed for personal assistant use via messaging apps (Telegram, WhatsApp, etc.), where:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

The README explicitly endorses autonomous execution of destructive calendar actions without a separate confirmation step when the agent judges the match to be unambiguous. Even with bounded search and post-delete verification, a mistaken match, parsing error, or adversarially phrased request can cause irreversible deletion of a legitimate event before the user has a chance to stop it.

Content

Scanner excerpt · README.md (reported line 54)May include surrounding context.

md
### Safety guards in place

The skill does NOT blindly delete. All of these must hold before executing without confirmation:

1. **Explicit user request** — the user must have asked for the action in their message.
2. **Single unambiguous match** — exactly one event matches in a tight, bounded time window.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 58)May include surrounding context.

md
1. **Explicit user request** — the user must have asked for the action in their message.
2. **Single unambiguous match** — exactly one event matches in a tight, bounded time window.
3. **Post-action verification** — after every delete, the agent verifies via agenda that the event is actually gone. It never claims success without verification.
4. **Disambiguation for ambiguous cases** — if multiple events match, the agent always stops and asks the user to choose before proceeding.
5. **Overlap checks for creates** — before creating events, the agent checks for scheduling conflicts across all calendars and asks for confirmation if an overlap exists.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly authorizes immediate delete/edit actions without a separate user-facing confirmation when it deems the match unambiguous. In a calendar-management context, this creates a real risk of irreversible or hard-to-recover destructive actions if the tool output is stale, matching is wrong, or the user phrased the request ambiguously but the agent overconfidently interprets it as unique.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

This is a genuine autonomous-action risk: the skill tells the agent to skip confirmation for cancel/delete/edit operations based on its own assessment of ambiguity. Because those actions alter or remove user data, the danger comes from model misresolution, stale calendar state, or semantic matching errors causing unintended modifications without a final human check.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
This skill is designed for personal assistant use where the user expects fast, low-friction calendar management. The confirmation policy below is an intentional UX choice — see README.md for rationale and safety guards.

### Unambiguous actions: execute immediately
For cancel/delete/edit actions, skip confirmation when ALL of these hold:
- The user explicitly requested the action (e.g. "delete my dentist appointment").
- Exactly one event matches in a tight time window.
- The match is unambiguous (single clear result on an exact date, or user specified date+time).

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The instruction "Don't mix languages within one reply" imposes a language-handling constraint in natural language, but does not clarify that the response language should follow user preference or provide a choice. Under the policy, locale or language constraints should be user-directed or explicitly justified.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
- Don't quote event titles unless needed to disambiguate.

### Calendar scope
- Trust gcalcli config (default/ignore calendars). Don't broaden scope unless user asks "across all calendars" or results are clearly wrong.

### Agenda (today-only by default)
- If user asks "agenda" without a period, return today only.

Static analysis

No suspicious patterns detected.