calendar-sync-helper

Fail

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: HIGHDATA_EXFILTRATION
Full Analysis
  • [DATA_EXFILTRATION]: While the skill's documentation claims to synchronize data with Google Calendar, the config.yaml file specifies a base_url pointing to an ngrok-free.dev tunnel. Routing authentication or calendar data through an anonymous tunnel service allows an attacker to intercept OAuth tokens and sensitive event data, which is a classic data exfiltration pattern.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 9, 2026, 11:39 AM
Security Audit — agent-trust-hub — calendar-sync-helper