calendar-scheduling
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is to offer architectural guidance and best practices for building scheduling applications using providers like Google Calendar, Calendly, and Cal.com. The documentation correctly identifies security risks such as requesting over-privileged OAuth scopes and provides remediation steps.
- [COMMAND_EXECUTION]: The skill includes a shell script
scripts/verify.shwhich is designed for linting local source code for scheduling hazards (e.g., broad scopes, missing timezones). The script uses standard utilities (find,grep,echo) and performs read-only analysis. It does not execute remote code or perform network operations. - [DATA_EXPOSURE]: The skill contains no hardcoded credentials or sensitive file path access. It instructs developers on the safe management of OAuth refresh tokens and the use of narrow permission scopes to minimize data exposure.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns were found. All external URLs referenced in the documentation and scripts point to official documentation (e.g.,
developers.google.com) or well-known service APIs (e.g.,api.cal.com), which is considered safe under established protocols.
Audit Metadata