ops-calendly
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The script
scripts/ops_calendly.pyreads sensitive authentication data from~/.config/ops-google-calendar/token.jsonto perform Google Calendar operations. Accessing files in the user configuration directory for authentication tokens represents a credential exposure risk.- [COMMAND_EXECUTION]: The skill executes external CLI tools viasubprocess.run. Specifically,scripts/ops_calendly.pyuses the GitHub CLI (gh) to update repository secrets, andscripts/sanity.pyexecutes the skill's entry scriptrun.shfor internal testing purposes.- [DATA_EXFILTRATION]: The skill performs network operations to external endpoints includingapi.calendly.comand Google's API services viahttpx. This includes transmitting theCALENDLY_PATsecret to GitHub's infrastructure when the secret management command is authorized by the user.- [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests data from external API responses and local JSON fixtures (e.g., in_read_calendlyand_load_jsonwithinscripts/ops_calendly.py). The skill relies on structured data validation but lacks explicit prompt boundary markers in the instructions to protect against instructions potentially embedded in external meeting metadata or user-supplied repository names.
Audit Metadata