Back to skill

Security audit

Google Calendar CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Google Calendar CLI guide, but users should treat its OAuth access and third-party CLI install with normal caution.

Before installing, verify that steipete/tap/gogcli is the intended CLI source, grant only the Google Calendar access you need, and test create/update scripts on a non-critical calendar before using --no-input or bulk loops on real calendar data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Third-Party CLI Installation from an External Homebrew Tap

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 12
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable code:

bash
brew install steipete/tap/gogcli

Technical Analysis

The installation instruction retrieves and installs the gogcli formula from the non-default Homebrew tap steipete/tap. It does not pin an immutable version, commit, formula revision, checksum, or signed release artifact. Consequently, the code installed when a user follows this instruction may differ from the dependency that was available when the Skill was reviewed.

The project contains only SKILL.md; it does not include the dependency implementation or verification data needed to audit the installed executable. There is no evidence in the reviewed project that the named package is currently malicious. The risk arises from the mutable, externally controlled supply-chain boundary and the absence of integrity controls.

Attack Path

  1. An attacker compromises the third-party tap, its upstream release process, a maintainer account, or a distribution artifact.
  2. The attacker publishes a modified formula or executable under the expected package name.
  3. A user follows the documented brew install steipete/tap/gogcli instruction.
  4. Homebrew retrieves and installs the modified dependency without validation against a project-specified immutable revision or checksum.
  5. The user invokes gog and supplies OAuth credentials or authorizes Google Calendar access as directed by the subsequent authentication workflow.
  6. The compromised executable runs with the user's local privileges and may access credentials, calendar information, or other resources available to that user.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user running Homebrew or invoking gog. The compromised executable could access files readable by that user, ...[truncated 473 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed, immutable release or formula commit instead of relying on the current state of a mutable tap.
  2. Document the canonical upstream repository and the exact approved version.
  3. Publish and verify a cryptographic checksum or trusted signature for the downloaded release artifact before installation.
  4. Where practical, use a versioned formula with a locked source URL and checksum, and retain the reviewed formula revision in project documentation.
  5. Advise users to inspect the Homebrew formula and its source URL before installation.
  6. Perform initial authentication and execution in a least-privilege environment, granting only the required Google Calendar scope.
  7. Add dependency update procedures requiring security review before changing the pinned version, formula revision, checksum, or signing key.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

Authentication Setup

bash
# Set up OAuth credentials
gog auth credentials /path/to/client_secret.json

# Add your Google account with calendar access
gog auth add you@gmail.com --services calendar

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill documents commands to create, update, and script bulk calendar operations, including non-interactive usage, but does not warn that these actions can modify or overwrite real calendar data at scale. In an agent context, this increases the chance of accidental destructive changes such as mass event creation, incorrect updates, or unintended deletions if similar commands are extended, especially when automation and default-account settings are encouraged.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.