calendar-sync-helper

Warn

Audited by Socket on Sep 9, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is plausible, but the skill omits critical details about authentication and directs sync traffic to an unspecified configurable endpoint instead of explicitly to official Google Calendar API endpoints. The footprint is not overtly malicious, but the unverified data flow prevents a benign classification.

Confidence: 84%Severity: 58%
AnomalyLOW
config.yaml

The configuration contains a supply-chain and credential-routing concern because OAuth callback traffic is directed to a public ngrok tunnel domain. This warrants verification of domain ownership, tunnel destination, token handling, and OAuth redirect configuration. No direct malware or executable malicious behavior is present in this fragment.

Confidence: 93%Severity: 62%
Audit Metadata
Analyzed At
Sep 9, 2026, 11:40 AM
Package URL
pkg:socket/skills-sh/cisco-ai-defense%2Fskill-scanner%2Fcalendar-sync-helper%2F@f92997feee7fcca24f14aba49530fa5c1c86d2a0374afbada6052f184892de74
Security Audit — socket — calendar-sync-helper