Back to skill

Security audit

Google Calendar Delete Event

Security checks for vulnerabilities and agentic risk

Overview

The skill is narrowly focused on deleting Google Calendar events, but it tells the agent to run a destructive delete command without requiring confirmation or event verification.

Only install this if you are comfortable with an agent deleting Google Calendar events through `gog`. Before use, require the agent to identify the exact calendar and event, restate what will be deleted, and get explicit confirmation before running the command.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill exposes a destructive command that permanently removes calendar events but provides no warning about its irreversible nature, no preconditions, and no operator guidance for safe use. In an automation context, the absence of warnings and safeguards materially increases the chance of accidental data loss and unsafe invocation by an LLM-based agent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger condition 'When an event needs to be removed or deleted from the calendar' is overly broad and does not require explicit user confirmation, identity verification of the target event, or any safety checks before executing a destructive action. In an agentic setting, this ambiguity can cause accidental or unauthorized deletion of calendar events from natural-language requests, inferred intent, or malformed upstream context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.