gws-calendar-agenda
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves calendar event details, including titles and descriptions, which are externally controlled inputs. This data represents a potential attack surface for indirect prompt injection. However, as the tool is restricted to read-only operations and does not have the capability to modify data or execute arbitrary system commands, the risk is categorized as low and is an expected part of the skill's utility.
Audit Metadata