Back to skill

Security audit

Garmin Trainer

Security checks for vulnerabilities and agentic risk

Overview

This Garmin training skill is coherent, but it needs review because it can automatically force-delete future Garmin workouts based only on a simple name prefix.

Review carefully before installing. The skill needs access to Garmin fitness and calendar data and can create scheduled workouts. On re-runs, require the agent to show the exact workouts it plans to remove and get your approval before deletion, especially for any W-prefixed workouts you may have created yourself.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:217
Finding

Weak Workout Ownership Check Can Delete User-Created Schedule Entries

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 217-219
Related Command Location: references/gccli-commands.md, lines 216-220
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Code

From SKILL.md:

text
Before scheduling new workouts, automatically remove all existing future scheduled workouts created by this skill (identifiable by the "W" prefix naming convention like "W3 Tempo Run"). Do not ask for confirmation — these are skill-managed workouts. For workouts that don't match the W-prefix pattern (user-created), leave them in place and schedule around them.

Related deletion command from references/gccli-commands.md:

bash
# Remove automatically without confirmation — these are skill-created:
gccli workouts schedule remove <schedule-id> --force

Technical Analysis

The Skill uses a generic W1 through W12 workout-name prefix as the ownership test for destructive cleanup. A name is not reliable provenance metadata: users and other integrations can independently create workouts whose names match this convention.

Consequently, the Skill may classify an unrelated workout as Skill-managed and pass its schedule ID to a forced removal command. The --force option and explicit instruction not to request confirmation remove the final opportunity for the user to detect the incorrect classification.

This behavior also conflicts with the stated requirement to preserve user-created workouts. The naming convention alone cannot establish whether this Skill created an entry.

Attack Path

  1. A user or another Garmin integration creates and schedules a workout with a name such as W3 Tempo Run.

  2. The user reruns the Garmin Trainer Skill.

  3. The Skill lists future scheduled workouts.

  4. It treats the matching W prefix as proof that the workout belongs to the Skill.

  5. It extracts the unrelated entry's schedule ID.

  6. It runs:

    bash
    gccli workouts schedule remo
    

...[truncated 639 chars]

Remediation
View remediation

Remediation Suggestions

  1. Record the exact workout IDs and schedule IDs created by the Skill in dedicated state, then delete only entries whose identifiers match that state.
  2. If Garmin supports custom metadata, tags, or descriptions, add a collision-resistant ownership marker and verify both the marker and stored identifier before deletion.
  3. Do not treat a human-readable naming convention as proof of ownership.
  4. If ownership cannot be conclusively established, preserve the entry or present the candidate entries to the user and require explicit confirmation.
  5. Avoid --force for ambiguous entries. Reserve forced deletion for entries whose ownership has been verified through stable identifiers.
  6. Handle stale or missing state conservatively: reconstruct the plan around uncertain entries rather than deleting them.
  7. Add collision tests covering user-created and third-party workouts named with W1 through W12 prefixes.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description contains very broad trigger language such as general training plans, race preparation, fitness building, and weekly workouts, which can cause the skill to activate in many ordinary fitness conversations. This increases the chance of unintended invocation of a skill that reads Garmin data and modifies the user's training calendar, creating a meaningful consent and safety issue even if no code execution is involved.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description does not clearly warn users that the skill will create workouts on their Garmin calendar and automatically delete future workouts previously created by the skill on re-runs. Because the skill performs state-changing actions against a user's calendar, omission of this behavior undermines informed consent and can lead to unexpected loss or alteration of scheduled training data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The prose claims only W-prefix, skill-created workouts are targeted, but the shown command accepts any schedule-id and forcefully deletes it with no provenance enforcement. This mismatch is dangerous because downstream agents may rely on the documentation's safety claim while actually performing unrestricted deletion of legitimate user-scheduled workouts.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The skill instructs the agent to automatically remove future scheduled workouts created by the skill and explicitly says not to ask for confirmation. This is dangerous because it authorizes destructive calendar changes based on a naming convention, which may misidentify workouts or remove items the user did not expect to be deleted, especially during re-runs or naming collisions.

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

md
- If training status shows overreaching, reduce intensity and volume
- Check if any new events were added and restructure phases accordingly

Before scheduling new workouts, automatically remove all existing future scheduled workouts created by this skill (identifiable by the "W" prefix naming convention like "W3 Tempo Run"). Do not ask for confirmation — these are skill-managed workouts. For workouts that don't match the W-prefix pattern (user-created), leave them in place and schedule around them.

See `references/gccli-commands.md` — "Scheduling & Cleanup" section for commands.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document explicitly instructs use of a force-delete command for scheduled workouts without any confirmation or validation step. In this skill context, deleting calendar entries is a destructive action, and the command as written can remove arbitrary scheduled workouts rather than only narrowly scoped, skill-owned items.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cleanup section documents a destructive operation without any warning, review, or approval safeguard despite affecting a user's Garmin schedule. In a training-plan skill, schedule integrity matters, so undocumented or unguarded deletion behavior increases the risk of accidental loss of planned workouts and user trust damage.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The phrase 'Remove automatically without confirmation' authorizes autonomous destructive action in a user calendar context. Because the skill manages training schedules over a 12-week window, autonomous deletion can silently alter or erase user plans, especially if the wrong schedule IDs are selected.

Content

Scanner excerpt · references/gccli-commands.md (reported line 217)May include surrounding context.

Remove skill-managed workouts (W-prefix)

Remove automatically without confirmation — these are skill-created:

bash
gccli workouts schedule remove <schedule-id> --force

Static analysis

No suspicious patterns detected.