Back to skill

Security audit

骑行&健康(Garmin/iGPSPORT/Intervals.icu/Strava/Xingzhe)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed workflow guide for a cycling-health CLI, with sensitive account access and sync actions gated by previews, local credential handling, and explicit user authorization.

Before installing, be aware that this skill can guide an agent to use an external CLI with your Garmin, Intervals.icu, iGPSPORT, Strava, and Xingzhe accounts. Keep secrets in local terminal prompts or protected files, review previews before any sync or settings/event change, and only approve overwrites, deletes, credential revocation, or full historical syncs when you understand the effect.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.