Skip to content
Back to skills

Online Calendar

ASecurity

Use when the user asks to view or change their Google Calendar. Do not use for daily planning.

  • 4 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 2, 2026
ai-agentspythongoapisecurity

Works with

  • cli
  • api
  • mcp

Security analysis

A100/100

Pro scans all 17 files and shows the line behind each finding

Scanned September 20, 2026

npx -y skills add MoeenNehzati/famulus --skill online-calendar --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Online Calendar?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Online Calendar
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/moeennehzati-online-calendar/badge)](https://www.skillsdirectory.com/skills/moeennehzati-online-calendar)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: online-calendar
description: >-
  Use when the user asks to view or change their Google Calendar. Do not use for daily planning.
---

<!-- BEGIN BLUEPRINT INTERFACES -->
> Generated from `blueprint.yaml`. Do not edit this block by hand.

### Managed setup

When first exposed to this skill in a session, invoke `famulus_dispatcher.invoke_security_2` once with:

```json
{
  "caller": "online-calendar",
  "interface": "online-calendar.interface.setup",
  "version": 2,
  "arguments": {
    "positionals": [],
    "options": {},
    "stdin": null
  }
}
```

Do not repeat this initial call during the session. Obtain permission before carrying out setup, then follow the returned setup-manager instructions exactly. If the result is busy or failed, stop and report it.

Executable Interfaces:

Send the required `caller` (caller skill), `interface`, `version`, and `arguments`; optional `dry_run` defaults to false. Compact uses ordered `positionals` plus an option mapping; ordered raw argv uses `positionals: []` plus every argv token in list `options`. Never mix forms.
- `online-calendar._rtx.interface.scripts-gcal` — Query or modify Google Calendar events via the Python calendar CLI (agenda, search, create, update, delete, etc.).
  - Caller: `online-calendar`
  - Version: 1
  - Security level: 2
  - Alternative: `token-or-calendars`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {}, "positionals": ["token"], "stdin": null}
    Required options: []; positional arity: 1..1; stdin: forbidden
  - Alternative: `create-calendar`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {"--color-id": "ID", "--description": "TEXT", "--summary": "TEXT", "--timezone": "TZ"}, "positionals": ["create-calendar"], "stdin": null}
    Required options: ["--summary"]; positional arity: 1..1; stdin: forbidden
  - Alternative: `agenda`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {"--all-calendars": true, "--calendar": "ID", "--days": "N", "--from": "ISO", "--to": "ISO"}, "positionals": ["agenda"], "stdin": null}
    Required options: []; positional arity: 1..1; stdin: forbidden
  - Alternative: `search`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {"--all-calendars": true, "--calendar": "ID", "--days": "N", "--from": "ISO", "--to": "ISO"}, "positionals": ["search", "QUERY"], "stdin": null}
    Required options: []; positional arity: 2..2; stdin: forbidden
  - Alternative: `get`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {"--calendar": "ID", "--event-id": "ID"}, "positionals": ["get"], "stdin": null}
    Required options: ["--event-id"]; positional arity: 1..1; stdin: forbidden
  - Alternative: `create`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {"--all-day": true, "--calendar": "ID", "--description": "TEXT", "--end": "ISO", "--location": "TEXT", "--start": "ISO", "--summary": "TEXT", "--timezone": "TZ"}, "positionals": ["create"], "stdin": null}
    Required options: ["--end", "--start", "--summary"]; positional arity: 1..1; stdin: forbidden
  - Alternative: `update`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {"--calendar": "ID", "--description": "TEXT", "--end": "ISO", "--event-id": "ID", "--location": "TEXT", "--start": "ISO", "--summary": "TEXT", "--timezone": "TZ"}, "positionals": ["update"], "stdin": null}
    Required options: ["--event-id"]; positional arity: 1..1; stdin: forbidden
  - Alternative: `delete`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {"--calendar": "ID", "--event-id": "ID"}, "positionals": ["delete"], "stdin": null}
    Required options: ["--event-id"]; positional arity: 1..1; stdin: forbidden
  - Alternative: `move`
    Arguments JSON (replace labels with actual values). Omit optional positionals and options that are not needed.
    {"options": {"--event-id": "ID", "--from": "CALENDAR_ID", "--to": "CALENDAR_ID"}, "positionals": ["move"], "stdin": null}
    Required options: ["--event-id", "--to"]; positional arity: 1..1; stdin: forbidden

Instruction Interfaces:

These are LLM-readable instruction surfaces. Read and follow them directly; do not invoke the MCP server for them.
- `connect-google.interface.default@1` — Route Google OAuth-client preparation according to whether a valid Desktop client is already installed.
<!-- END BLUEPRINT INTERFACES -->
# Google Calendar

Use `online-calendar._rtx.interface.scripts-gcal` for calendar reads and writes. Invoke one
interface call per operation, minimize network round trips, and issue independent calls
in parallel. Use the public process contract for complete subcommand and option shapes;
do not improvise invocation forms. Prefer the `--all-calendars` mode for schedule-wide
agenda or search requests.

Reads may proceed directly. Create, update, and delete requests may proceed when
the user supplied the necessary details for create, update, or delete. Confirm first
when adding attendees because it sends invitations, and before deleting an event that
has attendees or is far in the future. Treat `move` as authorized only when the user
explicitly asked to move the identified event to the named destination calendar.
Report each mutation's title, time, calendar, and link when available.

## Routing calendar operations

Use `calendars` when the target calendar is unknown. Before `create`, match the event to
the available calendar names. Use a clear match without asking; ask when multiple or no
calendars plausibly fit. Do not silently use `primary` when another calendar is clearly
more appropriate.

Agenda and search results are bounded to 50 events and do not paginate. Disclose that
bound when the requested range may contain more results. Recurrence, attendees, and
free-busy lack dedicated modes. For a genuine one-off unsupported API operation, use
the declared token mode only when direct API access is explicitly in scope, keep the
token secret, and apply the same confirmation rules. Prefer extending the public
interface for repeated use.

## Verify writes

Through `online-calendar._rtx.interface.scripts-gcal`, verify every create and delete and every
nontrivial update. The only exception is a metadata-only update limited to summary,
description, or location.

- After `create`, fetch the returned event ID and compare start, end, summary,
  location, and description with the request. On mismatch, delete the new event and
  report the intended and observed values.
- Before `update`, fetch and retain the fields being changed. Fetch again afterward.
  On mismatch, restore the retained values and report the discrepancy.
- After `delete`, fetch the event and require status `cancelled`; Google soft-deletes
  events rather than returning not-found. If it remains confirmed, report failure.

When completion is uncertain, inspect current event state before retrying; repeated
creates can produce duplicates.

## Google authorization

For setup or reauthorization, invoke `connect-google.interface.default`. Its
deterministic coordinator creates a credential file, asks Calendar's owner to
probe live access, and stores the path only after verification. Treat only
`complete: true` as successful setup; report any incomplete Calendar result and
retry through connect-google with the same file.

Existing legacy Calendar credentials remain runtime-readable until a verified
credential-file binding replaces them. Do not offer legacy setup as a new route.
Replacing the single active Calendar account requires explicit confirmation.

Files in this skill

  • SKILL.md7.9 KB
  • _rtx/__init__.py62 B
  • _rtx/_ensure_oauth.py12 KB
  • _rtx/_gcal_client.py17.9 KB
  • _rtx/_oauth_bootstrap.py7.2 KB
  • _rtx/blueprint.yaml3.1 KB
  • _rtx/blueprints/rtx-ensure-oauth.yaml19.1 KB
  • _rtx/blueprints/rtx-gcal-client.yaml14.9 KB
  • _rtx/blueprints/rtx-init.yaml360 B
  • _rtx/blueprints/rtx-oauth-bootstrap.yaml7.9 KB
  • _rtx/tests/test_calendar_credential_file_binding.py13.6 KB
  • _rtx/tests/test_calendar_oauth_transaction.py3 KB
  • _rtx/tests/test_g_calendar_ensure_oauth.py5.2 KB
  • _rtx/tests/test_g_calendar_guidance.py3.9 KB
  • _rtx/tests/test_gcal.py11.4 KB
  • blueprint.yaml2.3 KB
  • blueprints/gateway.yaml3.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…