apple-calendar

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses os.shell.run to execute local macOS commands including icalBuddy for reading calendar data and osascript for creating new events.
  • [EXTERNAL_DOWNLOADS]: The skill includes a setup playbook that offers to install the ical-buddy utility using the Homebrew package manager (brew install ical-buddy) if the command is not found on the system.
  • [COMMAND_EXECUTION]: Provides instructions to open macOS System Settings using the open command with a specific URI scheme (x-apple.systempreferences:...) to help users grant the necessary calendar permissions.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources (calendar event titles, locations, and notes) via icalBuddy. While this represents a potential injection surface where malicious instructions could be embedded in calendar entries, the skill provides clear boundaries and the operations (reading/writing events) are limited in scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:53 PM
Security Audit — agent-trust-hub — apple-calendar