extension-email-calendar-events

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied information for calendar event creation and updates, including event summaries, descriptions, and locations. This data is subsequently distributed via email to attendees, representing a surface for indirect prompt injection where malicious instructions could be embedded in the event details.
  • Ingestion points: The addCalendarEvent and updateEventDetails functions in src/backend/main.mo receive external text input through their arguments.
  • Boundary markers: The skill does not employ delimiters or specific warnings to distinguish user-provided content from system instructions in the invitations sent via email.
  • Capability inventory: The skill has the capability to send external communications via CalendarEvents.sendCalendarEvent in src/backend/main.mo.
  • Sanitization: No sanitization or validation logic for these text fields is implemented in the provided source code, which is typical for data storage tasks.
  • [EXTERNAL_DOWNLOADS]: The skill configuration in SKILL.md identifies dependencies on Motoko modules including caffeineai-email-calendar-events, caffeineai-email, and caffeineai-authorization via the mops package manager.
  • The referenced modules are vendor resources associated with the skill author, 'caffeinelabs', and are used for standard functional requirements such as authorization and email delivery.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 04:06 PM
Security Audit — agent-trust-hub — extension-email-calendar-events