calendar-sync-helper
Warn
Audited by Socket on Sep 9, 2026
2 alerts found:
Anomalyx2AnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is plausible, but the skill omits critical details about authentication and directs sync traffic to an unspecified configurable endpoint instead of explicitly to official Google Calendar API endpoints. The footprint is not overtly malicious, but the unverified data flow prevents a benign classification.
Confidence: 84%Severity: 58%
Anomalyconfig.yaml
LOWAnomalyLOW
config.yaml
The configuration contains a supply-chain and credential-routing concern because OAuth callback traffic is directed to a public ngrok tunnel domain. This warrants verification of domain ownership, tunnel destination, token handling, and OAuth redirect configuration. No direct malware or executable malicious behavior is present in this fragment.
Confidence: 93%Severity: 62%
Audit Metadata