google-calendar
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- Safe Data Handling: The skill provides specific instructions to ensure calendar data is handled safely, such as bounding searches with explicit time windows and paging large result sets to prevent context overflow.
- Write Safety Considerations: The instructions include a dedicated 'Write Safety' section that requires the agent to preserve existing event details and explicitly identify calendars or events before performing edits. This reduces the risk of unintended data modification.
- Indirect Prompt Injection Surface (Category 8): The skill processes external data (event notes and attachments) which could contain malicious instructions. This ingestion point in SKILL.md lacks explicit boundary markers, but the risk is mitigated by a capability inventory (update_event) that requires restating qualifying sets and human-in-the-loop confirmation (sanitization).
- Confirmation of Intent: High-impact actions, such as deletes or bulk updates, are treated as sensitive, requiring the agent to restate the target data before application, which ensures user oversight.
Audit Metadata