pp-calendly

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the calendly-pp-cli tool using npx -y @mvanhorn/printing-press-library and go install github.com/mvanhorn/printing-press-library/.... These resources are hosted on GitHub and NPM and are associated with the skill author context provided.\n- [DATA_EXFILTRATION]: The CLI tool includes a --deliver webhook: flag which allows the agent to POST command output, containing potentially sensitive Calendly account data, to an arbitrary external URL.\n- [COMMAND_EXECUTION]: Instructions describe parsing user-provided $ARGUMENTS to execute commands via the calendly-pp-cli binary, which may lead to command injection if the input is not properly sanitized before being passed to the shell.\n- [PROMPT_INJECTION]: The skill ingests data from external Calendly API sources, which introduces a surface for indirect prompt injection.\n
  • Ingestion points: Data enters the context through API commands for scheduled events, event types, and user information as described in the Command Reference section of SKILL.md.\n
  • Boundary markers: No delimiters or safety instructions are provided to the agent for handling retrieved API data to prevent it from being interpreted as instructions.\n
  • Capability inventory: The skill uses the Read Bash tool to execute a binary with network access and automated data delivery capabilities.\n
  • Sanitization: API responses are processed and delivered to the agent's context without specified filtering or validation of the external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 09:41 AM
Security Audit — agent-trust-hub — pp-calendly