Back to skill

Security audit

Health Guardian

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a local Apple Health importer and analyzer, but it handles sensitive health data while giving misleading privacy and automation guidance.

Review before installing. This skill is not clearly malicious, but it processes highly sensitive health records, encourages ongoing scheduled monitoring, and makes an inaccurate local-only privacy claim despite iCloud-based setup. Use it only with explicit consent from the person whose data is monitored, confirm whether any alerts leave the device, and restrict it to the intended export and data directories.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/import_health.py:137
Finding

Unbounded ZIP and CSV Processing Enables Resource Exhaustion

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code does partially align with the Apple Health integration claim: it accesses Apple Health export data and imports metrics such as heart rate, blood oxygen, respiratory rate, temperature, sleep, and wheelchair/push activity. However, its actual function is limited to ingestion and normalization of exported data into a local JSON file. There is no code for proactive monitoring, trend or pattern analysis, anomaly detection, alert generation, notification triggers, or any care-oriented decision logic for chronic conditions. Therefore, the description materially overstates the implemented behavior and primary purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill handles medical data and documents use of iCloud Drive sync, plus an alert channel that may be Telegram, but it does not prominently warn users that sensitive health information may be transmitted to third-party services. In the context of chronic-condition monitoring, omitted disclosure increases privacy, compliance, and user-safety risk because alerts and raw exports may traverse external platforms.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill documents file-based capabilities such as reading from an iCloud-synced export directory and writing health data into local files, but it does not declare any explicit tool scope or permission boundary. For a skill handling sensitive medical data, this lack of declared access scope weakens reviewability and increases the risk of over-broad file access or unintended data exposure by the hosting agent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that nothing leaves the machine and there is no cloud or telemetry, yet its primary ingestion path depends on iCloud Drive synchronization through Health Auto Export. Because the data involved is highly sensitive health information, this misleading privacy claim can cause users to enable the skill under a false assumption about data residency and third-party exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code loads health readings from a local JSON file, which is sensitive personal data, but provides no visible warning, prompt, or privacy disclosure to the user in the script itself. The existing docstrings describe functionality but do not warn that personal health data will be accessed and analyzed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The natural-language config value points to a macOS/iCloud-specific default path, which can impose a specific platform environment by default rather than offering a user-selected or documented alternative. This may conflict with policy expectations around not forcing a locale or environment assumption without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest-style config sets "import_interval": "hourly" but does not clarify when imports should or should not run, what event starts them, or any limiting conditions. In a manifest/config file, this kind of broad scheduling can function as an ambiguous activation condition because the trigger scope is underspecified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.