gws-calendar

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to execute the gws command-line tool to interact with Google Calendar APIs. It relies on the presence of this binary in the environment to perform all listed operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes untrusted data from external sources (Google Calendar events, descriptions, and ACLs).
  • Ingestion points: Data is ingested through methods like events.list, events.get, and calendarList.list described in SKILL.md.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are defined within this file, though it references a shared security configuration in ../gws-shared/SKILL.md.
  • Capability inventory: The skill has high-impact capabilities including calendars.clear (deleting all events), acl.insert (modifying permissions), and events.delete.
  • Sanitization: There is no evidence of sanitization or validation of the content retrieved from the calendar API before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:12 AM
Security Audit — agent-trust-hub — gws-calendar