Back to skill

Security audit

GrowthLoop – Plan & Habit Tracker

Security checks across malware telemetry and agentic risk

Overview

This is a coherent local habit-tracking skill with disclosed reminders and local storage, and I found no evidence of exfiltration, hidden installation, or destructive behavior.

Install only if you are comfortable with a habit coach storing your habit history locally and checking reminder status during conversations. Avoid putting secrets in habit notes, and only configure external schedulers such as cron or webhooks if you explicitly want automated reminders.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases include common expressions such as '打卡', '今天完成了', and '汇报一下', which can appear in ordinary conversation unrelated to this skill. Overly broad triggers can cause unintended activation, leading to unnecessary data access, writes, or follow-up prompts without clear user intent. The risk is amplified here because activation may cascade into reading and updating persistent habit records.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill says heartbeat detection should run on every conversation and invoke a reminder check automatically, which is an ambiguous and overbroad activation rule. This can trigger code execution and access habit data even when the user is discussing unrelated topics, creating privacy and consent concerns. In this skill, the danger is higher because the automatic behavior is tied to persistent local storage and proactive reminders.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The skill stores habit data persistently in a local JSON file, but the description does not clearly warn users about this retention. Even if the data is not highly sensitive by default, habit logs can reveal health, productivity, or lifestyle patterns, so silent persistence undermines informed consent. The context makes this a meaningful privacy issue because the entire skill revolves around ongoing behavioral tracking over time.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal