Back to skill

Security audit

Google Calendar

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for Google Calendar management, but it asks users to install a mutable third-party CLI that will handle calendar credentials and private calendar data.

Install only if you trust Porteden and are comfortable giving its CLI access to your Google Calendar. Prefer a pinned, verified release if available, authorize the narrowest Google Calendar scope, use a separate profile or account for sensitive calendars, confirm every mutation carefully, and log out or revoke access when done.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:5
Finding

Unpinned Third-Party CLI Receives Sensitive Google Calendar Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 5–11
Vulnerability Type: Unpinned third-party dependency and mutable supply-chain installation
Risk Level: High

The Skill directs users to install the externally maintained porteden executable from a custom Homebrew tap or directly from the latest revision of a GitHub-hosted Go module:

yaml
metadata: {"openclaw":{"emoji":"📅","homepage":"https://porteden.com","primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"requires":{"bins":["porteden"]},"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
markdown
If `porteden` is not installed: `brew install porteden/tap/porteden` (or `go install github.com/porteden/cli/cmd/porteden@latest`).

Technical Analysis

The Go installation explicitly uses @latest, while the custom Homebrew formula also lacks an immutable version, commit, checksum, or signature requirement in the Skill. Consequently, the executable installed at a future date may differ from the artifact that was originally reviewed.

This is security-sensitive because the CLI is subsequently entrusted with a PE_API_KEY or credentials stored through porteden auth login. Its declared operation also exposes private calendar information to the executable, potentially including event descriptions, attendee email addresses, locations, meeting URLs, account identifiers, and availability data. It is also able to perform state-changing operations such as creating, updating, deleting, and responding to events.

The document contains useful safeguards, including confirmation before mutations, account profiles, logout ...[truncated 2453 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an explicitly audited, immutable semantic version or commit:
    bash
    go install github.com/porteden/cli/cmd/porteden@vX.Y.Z
    
  2. Pin the Homebrew installation to a versioned formula or bottle rather than relying on a mutable custom-tap head.
  3. Publish and verify cryptographic checksums or signatures before installation. Record the expected digest in reviewed Skill metadata or installation documentation.
  4. Prefer an official, reproducible distribution channel with provenance attestations, signed releases, and a documented vulnerability response process.
  5. Document every network endpoint contacted by the CLI and explain whether calendar data passes directly to Google or through an intermediary service.
  6. Document the precise OAuth scopes requested. Use read-only Calendar scopes by default and require a separate, explicit authorization step before granting mutation capabilities.
  7. Isolate accounts with --profile or PE_PROFILE, and authorize only the specific Google account and calendars required for the task.
  8. Avoid exposing credentials through broadly inherited process environments where possible. Continue storing credentials in a protected OS keyring, restrict access permissions, and revoke tokens after suspected exposure.
  9. Add dependency update review procedures so each version change triggers source review, provenance verification, and security testing before the pinned version is updated.
  10. Retain the existing confirmation requirements, but do not treat them as a defense against compromised dependency code.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: calendar-cli
description: Google Calendar - secure Google calendar management. Use when the user wants to list, search, or read Google Calendar events; creating, updating, deleting, or responding to events require explicit user confirmation (gog-cli & gws secure google-calendar firewall alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📅","homepage":"https://porteden.com","primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"requires":{"bins":["porteden"]},"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---

# porteden google-calendar

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
name: calendar-cli
description: Google Calendar - secure Google calendar management. Use when the user wants to list, search, or read Google Calendar events; creating, updating, deleting, or responding to events require explicit user confirmation (gog-cli & gws secure google-calendar firewall alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📅","homepage":"https://porteden.com","primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"requires":{"bins":["porteden"]},"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---

# porteden google-calendar

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
name: calendar-cli
description: Google Calendar - secure Google calendar management. Use when the user wants to list, search, or read Google Calendar events; creating, updating, deleting, or responding to events require explicit user confirmation (gog-cli & gws secure google-calendar firewall alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📅","homepage":"https://porteden.com","primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"requires":{"bins":["porteden"]},"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---

# porteden google-calendar

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
name: calendar-cli
description: Google Calendar - secure Google calendar management. Use when the user wants to list, search, or read Google Calendar events; creating, updating, deleting, or responding to events require explicit user confirmation (gog-cli & gws secure google-calendar firewall alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📅","homepage":"https://porteden.com","primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"requires":{"bins":["porteden"]},"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---

# porteden google-calendar

Static analysis

No suspicious patterns detected.