gcalcli-calendar

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to skip user confirmation for destructive actions like deleting or editing events when the match is unambiguous. This policy explicitly overrides standard safety guidelines that require human-in-the-loop verification for irreversible operations.\n- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill reads and processes external data from calendar event titles and descriptions which could contain malicious instructions designed to influence the agent.\n
  • Ingestion points: External data enters the agent context through the output of the gcalcli agenda and gcalcli search commands.\n
  • Boundary markers: No delimiters or instructions are used to distinguish between untrusted calendar data and the agent's core instructions.\n
  • Capability inventory: The agent can perform deletions, additions, and imports using the gcalcli tool based on its interpretation of the data.\n
  • Sanitization: There is no evidence of content sanitization or validation before the data is used in decision-making processes.\n- [COMMAND_EXECUTION]: The skill manages calendar entries by executing the gcalcli command-line interface with subcommands including agenda, search, add, import, and delete.\n- [EXTERNAL_DOWNLOADS]: The skill requires the gcalcli utility, which is a well-known open-source tool for Google Calendar management typically obtained from public package registries or its official GitHub repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:06 PM
Security Audit — agent-trust-hub — gcalcli-calendar