google-calendar

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes data from an external source (Google Calendar events) that may be controlled by third parties.
  • Ingestion points: The list_events and get_event tools in SKILL.md retrieve event summaries and descriptions from the user's calendar.
  • Boundary markers: The instructions lack boundary markers, delimiters, or explicit warnings for the agent to ignore instructions embedded within event data.
  • Capability inventory: The skill possesses capabilities to create, update, and delete events (create_event, update_event, delete_event), as well as list all calendars (list_calendars), which could be abused if the agent obeys instructions found in a processed event.
  • Sanitization: There are no instructions for sanitizing, escaping, or filtering content retrieved from the calendar API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 12:34 AM