Back to skill

Security audit

health-reasoner

Security checks across malware telemetry and agentic risk

Overview

This is a local lifestyle scoring tool with some documentation mismatches, but no evidence of hidden upload, credential access, destructive behavior, or automatic privileged execution.

Use this only as a local wellness habit scorer, not medical advice. Keep input and history files private, avoid entering detailed medical history, and do not install Flask unless you specifically intend to experiment with the unfinished API path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding
The skill advertises zero external dependencies and optional history, but the detected file read/write capability is not explicitly declared as a permission or clearly scoped. Undeclared filesystem access can surprise users and host systems, especially in agent environments where local files may contain sensitive data; even 'history' logging can become a privacy issue for health-related inputs.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The documented purpose does not fully match the broader behaviors identified, including local history storage, batch processing, trend analysis, and setup guidance for an API mode not reflected in the shown entrypoints. This mismatch undermines informed consent and security review because users may approve a simple local scoring tool while the skill also persists data or exposes expansion paths that increase attack surface, particularly for sensitive health-adjacent information.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.