google-calendar
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes data from an external source (Google Calendar events) that may be controlled by third parties.
- Ingestion points: The
list_eventsandget_eventtools inSKILL.mdretrieve event summaries and descriptions from the user's calendar. - Boundary markers: The instructions lack boundary markers, delimiters, or explicit warnings for the agent to ignore instructions embedded within event data.
- Capability inventory: The skill possesses capabilities to create, update, and delete events (
create_event,update_event,delete_event), as well as list all calendars (list_calendars), which could be abused if the agent obeys instructions found in a processed event. - Sanitization: There are no instructions for sanitizing, escaping, or filtering content retrieved from the calendar API before it is processed by the agent.
Audit Metadata