NYC

google-calendar

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • NO_CODE (LOW): The core implementation scripts (scripts/auth.py and scripts/gcal.py) referenced in the documentation are missing, which limits the ability to verify security practices regarding token handling and input validation.
  • PROMPT_INJECTION (LOW): The skill is susceptible to Indirect Prompt Injection (Category 8). 1. Ingestion points: Untrusted data enters via calendar event listings and details. 2. Boundary markers: Documentation does not indicate use of delimiters to isolate event content from system instructions. 3. Capability inventory: The skill allows for event creation, modification, and deletion based on AI instructions. 4. Sanitization: There is no description of sanitization for ingested event metadata like titles or descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 04:01 PM