Back to skill

Security audit

Google Calendar Update Time

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrowly scoped Google Calendar time-update helper with a disclosed CLI action, though users should ensure inputs are handled safely.

Install this only if you intend the agent to update Google Calendar events through the authenticated gog CLI. Prefer agents or runners that pass gog arguments as a structured argument list and validate calendar IDs, event IDs, and RFC3339 timestamps before execution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:18
Finding

Potential Command Injection Through Unvalidated CLI Arguments

Content
View full analysis
--from "..." --to "..."`] ## Schema Example ```json { "command": "gog calendar update primary event_id_123 --from \"2026-04-28T10:00:00Z\" --to \"2026-04-28T11:00:00Z\" --json" } ``` ``` ### Technical Analysis The skill instructs an agent to construct a terminal command using dynamic calendar identifiers, event identifiers, and timestamp values. It does not require strict validation of those values, shell-safe escaping, or execution through a structured argument array. The calendar and event identifiers are shown without quoting. The timestamp values are enclosed in double quotes, but the instructions do not prevent embedded quotation marks, command substitutions, or other shell metacharacters. If the execution environment passes the constructed command through a shell, an attacker-controlled value could terminate an argument and append an additional command. The example itself contains benign static values. Exploitation therefore depends on the agent substituting untrusted input into the documented command and executing the resulting string through a command shell. ### Attack Path 1. An attacker supplies a crafted calendar ID, event ID, or timestamp through a rescheduling request. 2. The agent inserts the supplied value directly into the documented command template. 3. The generated command is submitted to a shell rather than executed as a structured process argument array. 4. Shell metacharacters in the supplied value alter the intended command structure. 5. The injected command executes with the operating-system permissions and environment available to the agent p ...[truncated 971 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.