Back to skill

Security audit

Google 日历基础版

Security checks for vulnerabilities and agentic risk

Overview

This calendar skill is broadly coherent, but it needs Review because it asks for command execution and calendar credentials while giving inconsistent privacy, service-support, and trigger-scope instructions.

Review before installing. Use this only for explicit personal calendar tasks, prefer an isolated environment, pin or vet the gcalcli dependency, and do not rely on the local-only privacy claim. Calendar contents and credentials may be sent to Google or a configured CalDAV service, and delete operations should be confirmed before execution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:148
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 148 and 184
Vulnerability Type: Unpinned runtime dependency
Risk Level: Medium

Vulnerable Code

bash
pip install gcalcli

The same installation instruction appears twice, at lines 148 and 184.

Technical Analysis

The Skill instructs the user or AI Agent to install gcalcli without specifying a version, package hash, lock file, or trusted package index. Consequently, installation resolves whichever package version and transitive dependencies the configured Python Package Index supplies at execution time.

This makes the installed code mutable after the Skill has been reviewed. If the package, one of its dependencies, the package publisher account, or the configured package index is compromised, malicious code could be delivered through an otherwise legitimate-looking installation command. Python packages may execute attacker-controlled code during installation or when imported and invoked.

The audit did not identify evidence that gcalcli itself is malicious. The finding concerns the absence of dependency integrity and reproducibility controls.

Attack Path

  1. An attacker compromises a relevant package release, transitive dependency, publisher account, or package source used by pip.
  2. A user or Agent follows the Skill and runs pip install gcalcli.
  3. pip resolves and downloads the attacker-controlled package version or dependency because no approved version or hash is enforced.
  4. Malicious package code executes during installation or when calendar functionality is subsequently invoked.
  5. The code operates with the privileges and environmental access of the account running pip or gcalcli.

Impact Assessment

Successful exploitation could allow arbitrary code execution with the installing user's privileges. Depending on that account's permissions and environment, the compromised dependency could access local files, ...[truncated 233 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin gcalcli to a specifically reviewed version rather than installing the latest available release.
  • Maintain a lock file that fixes all transitive dependency versions.
  • Require cryptographic hashes for downloaded distributions, such as with a hash-locked requirements file and pip install --require-hashes.
  • Explicitly configure and document a trusted package index; do not permit untrusted extra indexes.
  • Prefer reviewed, signed release artifacts when available.
  • Install the dependency in an isolated virtual environment or container under a non-privileged account.
  • Add a controlled dependency-update process that includes provenance verification, vulnerability scanning, and functional review before changing pinned versions.
  • Replace both occurrences of the unpinned command, including the duplicate at line 184, with the hardened installation procedure.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill gives contradictory statements about CalDAV support, which can mislead an agent or user into configuring and connecting to an unintended external calendar service. In a tool with exec capability and credential setup instructions, this ambiguity increases the risk of sensitive credentials being entered, stored, or transmitted to the wrong backend.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions are much broader than the skill's actual calendar-management scope, encouraging invocation for unrelated analytics, reporting, and visualization tasks. Over-broad activation can cause an agent to select this exec-capable skill in the wrong context, leading to unnecessary command execution, external network access, or mishandling of user intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document claims all data remains local and is not uploaded to the cloud, yet the skill's core purpose requires interacting with Google Calendar and external APIs. This is dangerous because it can create a false sense of privacy, causing users to expose calendar contents, metadata, and credentials under materially incorrect data-handling expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description uses broad invocation language covering project management, task planning, progress tracking, and team collaboration, which exceeds the narrowly described gcalcli-based functionality. In an agent ecosystem, such over-claiming increases the chance of unintended activation and use of exec-enabled behavior for tasks the skill is not designed to perform safely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file states '支持中文交互' and presents the skill as Chinese-interaction oriented without indicating that users may choose another language. This can violate language/locale policy when a skill imposes a specific language absent user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

L041 明确写明 FREE 版本“团队协作:不支持”,但 L114-L120 的使用场景却以“创建团队会议”为示例并给出具体命令。这不是单纯信息不完整,而是对该版本能力边界的直接矛盾,容易误导代理或用户将个人版用于团队协作场景。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.