@tank/google-calendar

Pass

Audited by Gen Agent Trust Hub on May 31, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill connects to official Google API domains to perform calendar operations. Evidence: Network outbound permissions are restricted to *.googleapis.com, accounts.google.com, and oauth2.googleapis.com in tank.json.
  • [PROMPT_INJECTION]: Represents a surface for indirect prompt injection by processing external calendar event data. Ingestion points: event summaries and descriptions via Google API and local ICS files. Boundary markers: absent. Capability inventory: network write operations to create and modify calendar events. Sanitization: no documentation of input validation or sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
May 31, 2026, 11:04 PM
Security Audit — agent-trust-hub — @tank/google-calendar