ops-calendly

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The script scripts/ops_calendly.py reads sensitive authentication data from ~/.config/ops-google-calendar/token.json to perform Google Calendar operations. Accessing files in the user configuration directory for authentication tokens represents a credential exposure risk.- [COMMAND_EXECUTION]: The skill executes external CLI tools via subprocess.run. Specifically, scripts/ops_calendly.py uses the GitHub CLI (gh) to update repository secrets, and scripts/sanity.py executes the skill's entry script run.sh for internal testing purposes.- [DATA_EXFILTRATION]: The skill performs network operations to external endpoints including api.calendly.com and Google's API services via httpx. This includes transmitting the CALENDLY_PAT secret to GitHub's infrastructure when the secret management command is authorized by the user.- [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests data from external API responses and local JSON fixtures (e.g., in _read_calendly and _load_json within scripts/ops_calendly.py). The skill relies on structured data validation but lacks explicit prompt boundary markers in the instructions to protect against instructions potentially embedded in external meeting metadata or user-supplied repository names.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — ops-calendly