calendar-sync-helper
Fail
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: HIGHDATA_EXFILTRATION
Full Analysis
- [DATA_EXFILTRATION]: While the skill's documentation claims to synchronize data with Google Calendar, the
config.yamlfile specifies abase_urlpointing to anngrok-free.devtunnel. Routing authentication or calendar data through an anonymous tunnel service allows an attacker to intercept OAuth tokens and sensitive event data, which is a classic data exfiltration pattern.
Recommendations
- AI detected serious security threats
Audit Metadata