add-gcal-tool

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configures the container build process to install the @cocal/google-calendar-mcp package from the public npm registry.- [COMMAND_EXECUTION]: Executes shell commands to manage configuration files, restart system services (via launchctl/systemctl), and update the internal project database (data/v2.db) to register the MCP server and filesystem mounts.- [SAFE]: Implements a security-best-practice pattern by using stub credentials (onecli-managed) for OAuth. This ensures that actual sensitive tokens and secrets are never stored in the container environment or visible in the skill's instruction set.- [SAFE]: No malicious patterns such as obfuscation, unauthorized data exfiltration, or persistence mechanisms were detected in the provided files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 04:18 PM
Security Audit — agent-trust-hub — add-gcal-tool