skills/openai/plugins/google-calendar/Gen Agent Trust Hub

google-calendar

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • Safe Data Handling: The skill provides specific instructions to ensure calendar data is handled safely, such as bounding searches with explicit time windows and paging large result sets to prevent context overflow.
  • Write Safety Considerations: The instructions include a dedicated 'Write Safety' section that requires the agent to preserve existing event details and explicitly identify calendars or events before performing edits. This reduces the risk of unintended data modification.
  • Indirect Prompt Injection Surface (Category 8): The skill processes external data (event notes and attachments) which could contain malicious instructions. This ingestion point in SKILL.md lacks explicit boundary markers, but the risk is mitigated by a capability inventory (update_event) that requires restating qualifying sets and human-in-the-loop confirmation (sanitization).
  • Confirmation of Intent: High-impact actions, such as deletes or bulk updates, are treated as sensitive, requiring the agent to restate the target data before application, which ensures user oversight.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 03:18 PM
Security Audit — agent-trust-hub — google-calendar