pp-calendly
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the calendly-pp-cli tool using npx -y @mvanhorn/printing-press-library and go install github.com/mvanhorn/printing-press-library/.... These resources are hosted on GitHub and NPM and are associated with the skill author context provided.\n- [DATA_EXFILTRATION]: The CLI tool includes a --deliver webhook: flag which allows the agent to POST command output, containing potentially sensitive Calendly account data, to an arbitrary external URL.\n- [COMMAND_EXECUTION]: Instructions describe parsing user-provided $ARGUMENTS to execute commands via the calendly-pp-cli binary, which may lead to command injection if the input is not properly sanitized before being passed to the shell.\n- [PROMPT_INJECTION]: The skill ingests data from external Calendly API sources, which introduces a surface for indirect prompt injection.\n
- Ingestion points: Data enters the context through API commands for scheduled events, event types, and user information as described in the Command Reference section of SKILL.md.\n
- Boundary markers: No delimiters or safety instructions are provided to the agent for handling retrieved API data to prevent it from being interpreted as instructions.\n
- Capability inventory: The skill uses the Read Bash tool to execute a binary with network access and automated data delivery capabilities.\n
- Sanitization: API responses are processed and delivered to the agent's context without specified filtering or validation of the external content.
Audit Metadata