Back to skill

Security audit

Google Calendar Update Summary

Security checks for vulnerabilities and agentic risk

Overview

The skill is narrowly meant to rename a Google Calendar event, but its shell-command template creates a review-worthy command-injection risk.

Install only if you trust the gog CLI setup and the agent that will execute it. Event titles, event IDs, and calendar IDs should be passed as literal CLI arguments through a shell-free execution path or carefully validated/escaped before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:20
Finding

Shell Command Injection Through Unsafely Interpolated Calendar Parameters

Content
View full analysis
--summary "..."`] ## Schema Example ```json { "command": "gog calendar update primary event_id_123 --summary \"Updated Sync Meeting\" --json" ``` ### Technical Analysis The skill directs an agent to build and execute a shell command by placing the calendar ID, event ID, and requested summary directly into a textual command template. It does not require an argument-array execution API, input validation, or shell-safe escaping. The unquoted `` and `` placeholders are particularly exposed to shell metacharacter injection. Although the summary placeholder is surrounded by double quotes, this is not sufficient if a supplied summary contains quote characters, command substitutions, or other shell syntax. Directly substituting attacker-controlled content could therefore alter the command structure rather than passing the content exclusively as data to `gog`. The documented JSON command is also a serialized shell command string rather than a structured executable-and-arguments representation, encouraging unsafe concatenation and shell interpretation. ### Attack Path 1. An attacker controls or influences the calendar ID, event ID, or requested event summary supplied to the agent. 2. The attacker includes shell syntax in one of those values. For example, a malicious summary could close the quoted argument and append an additional command. 3. The agent interpolates the value into the documented command template. 4. The command is submitted to a shell rather than executed through a shell-free argument-array API. 5. The shell interprets the injected metacharacters and runs the ...[truncated 964 chars]
Remediation
View remediation
- - --summary - - --json ``` 2. Explicitly prohibit construction of a shell command string from user-controlled values. 3. Validate calendar and event identifiers against the narrowest syntax accepted by the service. Reject unexpected whitespace, control characters, and shell metacharacters where they are not valid identifier characters. 4. Treat the summary as opaque text and pass it as one literal process argument. Do not attempt to make it safe merely by surrounding it with quotation marks. 5. If shell execution is unavoidable, apply robust, platform-specific argument escaping to every dynamic value. Shell-free execution should remain the preferred control. 6. Update the skill documentation to state that the operation must modify only the summary and must not execute any command or option derived from summary contents. 7. Add negative tests using values containing quotes, semicolons, command substitutions, newlines, option prefixes, and other metacharacters. Confirm that each value reaches `gog` as a single literal argument. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.