Back to skill

Security audit

Google Calendar Update Event

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow Google Calendar event-update helper that clearly discloses its use of the local gog CLI, with no hidden code or persistence found.

Install this only if you want your agent to modify real Google Calendar events through gog. Make sure gog is authenticated to the intended Google account, and ask the agent to confirm the calendarId, eventId, and proposed changes before important updates.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.