Back to skill

Security audit

Fitlog

Security checks for vulnerabilities and agentic risk

Overview

FitLog is advertised as a workout tracker but the documentation and script implement a broader productivity logger that stores arbitrary local notes.

Review this carefully before installing. It is not just a workout logger as advertised; it functions as a general local productivity journal. Only use it if you are comfortable with arbitrary notes, reminders, and exports being stored in plaintext under your home directory, and avoid opening CSV exports in spreadsheets unless the data is trusted.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:6
Finding

Sensitive activity records are created without enforced restrictive permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:6-7 and entry-writing branches such as scripts/script.sh:140-151
Vulnerability Type: Insecure storage permissions for potentially sensitive data
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${HOME}/.local/share/fitlog"
mkdir -p "$DATA_DIR"

Entry-writing branches subsequently create plaintext log files without setting their permissions:

bash
add)
    shift
    if [ $# -eq 0 ]; then
        echo "Recent add entries:"
        tail -20 "$DATA_DIR/add.log" 2>/dev/null || echo "  No entries yet. Use: fitlog add <input>"
    else
        local input="$*"
        local ts=$(date '+%Y-%m-%d %H:%M')
        echo "$ts|$input" >> "$DATA_DIR/add.log"
        local total=$(wc -l < "$DATA_DIR/add.log")
        echo "  [Fitlog] add: $input"
        echo "  Saved. Total add entries: $total"
        _log "add" "$input"
    fi
    ;;

The same storage pattern is repeated for the other logging commands and for history.log.

Technical Analysis

FitLog is presented as a fitness, health, reminder, and activity-tracking tool. Its logs can therefore contain sensitive health information, schedules, habits, project details, and other personal data.

The script creates its data directory with mkdir -p and creates log files through ordinary append redirection. It does not set a restrictive umask, explicitly assign directory mode 0700, or assign file mode 0600. Effective permissions consequently depend on the invoking process's existing umask. In an environment with a permissive umask, the resulting files may be readable by other local users.

The data is also stored as unencrypted plaintext. Encryption is not always required for a local command-line application, but strict access permissions are necessary because of the potentially sensitive nature of the records.

Attack Path

  1. A victim runs ...[truncated 1116 chars]
Remediation
View remediation

Remediation Suggestions

Apply restrictive permissions before creating or writing any data:

bash
umask 077

DATA_DIR="${HOME}/.local/share/fitlog"
mkdir -p -m 700 "$DATA_DIR"
chmod 700 "$DATA_DIR"

Ensure every existing and newly created data file is accessible only to its owner:

bash
find "$DATA_DIR" -type f -exec chmod 600 {} +

Additional hardening should include:

  • Rejecting a HOME value that does not resolve to a directory owned by the current user.
  • Checking that DATA_DIR is not a symbolic link before writing sensitive records.
  • Documenting that entries and exports are stored locally in plaintext.
  • Applying mode 0600 to JSON, CSV, and text exports as well as log files.
  • Providing an optional secure deletion or retention mechanism for health-related records.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:78
Finding

User-controlled values can cause spreadsheet formula injection in CSV exports

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:78-86
Vulnerability Type: CSV injection and malformed CSV generation
Risk Level: Medium

Vulnerable Code

bash
csv)
    echo "type,time,value" > "$out"
    for f in "$DATA_DIR"/*.log; do
        [ -f "$f" ] || continue
        local name=$(basename "$f" .log)
        while IFS='|' read -r ts val; do
            echo "$name,$ts,$val" >> "$out"
        done < "$f"
    done
    ;;

Technical Analysis

The val field originates from user-controlled log input and is written directly into a CSV cell. The implementation does not perform CSV quoting, escape embedded double quotes, or neutralize values beginning with spreadsheet formula indicators such as =, +, -, or @.

As a result, an entry such as a spreadsheet formula is emitted verbatim. When a user opens the generated file in spreadsheet software, that software may interpret the value as a formula rather than inert text. Depending on the spreadsheet application, version, configuration, and security policy, formulas may initiate external requests, expose data through formula results, or otherwise perform unintended spreadsheet-level actions.

Embedded commas, quotes, carriage returns, and newlines also produce malformed or structurally altered CSV records. Proper CSV quoting alone addresses record integrity, but formula neutralization is separately required because a correctly quoted formula may still be evaluated by spreadsheet software.

Attack Path

  1. An attacker supplies, or persuades a user or agent to record, a FitLog value beginning with a spreadsheet formula indicator.
  2. The value is stored in a FitLog log file.
  3. The victim runs fitlog export csv.
  4. The export routine copies the attacker-controlled value into export.csv without escaping or neutralization.
  5. The victim opens the exported file in spreadsheet software.
  6. If the spreadshe ...[truncated 891 chars]
Remediation
View remediation

Remediation Suggestions

Replace direct echo serialization with a dedicated CSV-encoding function that:

  1. Converts each value to a single intended CSV field.
  2. Escapes every double quote by doubling it.
  3. Encloses every field in double quotes.
  4. Neutralizes fields whose first non-whitespace character is =, +, -, or @.
  5. Defines how embedded carriage returns and newlines are handled.

For exports intended for spreadsheet use, prefix formula-like values with an apostrophe or another documented neutralization marker before CSV encoding. For example:

bash
neutralize_spreadsheet_value() {
    local value="$1"

    case "$value" in
        ["=+@-"]*) value="'$value" ;;
    esac

    value=${value//\"/\"\"}
    printf '"%s"' "$value"
}

Construct records with printf rather than echo, and encode every field consistently. Add tests covering formula prefixes, commas, double quotes, empty values, Unicode text, and embedded line breaks. If preservation of exact raw values is required, consider JSON as the primary machine-readable format and clearly warn that CSV exports must be treated as untrusted data when opened in spreadsheet software.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill metadata claims a workout logging tool, but the body documents a generic productivity and task-tracking utility with substantially broader behavior. This kind of scope mismatch is dangerous because agents may invoke the skill in fitness contexts while actually exposing unrelated logging, export, search, and archival capabilities, undermining user expectations and policy-based routing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The frontmatter advertises health and workout tracking, while the main content describes a productivity toolkit. This inconsistency can cause trust boundary failures: automated selection systems or users may approve the skill based on benign-seeming health functionality, but the actual documented usage is materially different and broader.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented behavior across most of the file is for broad productivity logging rather than workout tracking. In agent ecosystems, this is dangerous because capability descriptions are often used for tool selection and safety decisions; misleading documentation can result in inappropriate invocation, unexpected data collection, and bypass of user intent constraints.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The implementation materially diverges from the declared workout-tracking purpose and instead provides a broad, generic logging toolkit. This kind of scope mismatch is dangerous because users or higher-level agents may grant access or invoke the skill under fitness-related assumptions, while it actually captures arbitrary free-form notes across generic categories, increasing the risk of unintended data collection and misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's scope is inconsistent and overly broad at the point where users and orchestrators determine whether to invoke it. Ambiguous invocation boundaries increase the chance the agent uses the skill in unintended contexts, leading to over-collection of user data or execution of features the user did not expect from a workout logger.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The inline documentation repeatedly labels the tool as a productivity utility rather than a workout logger, contradicting the published metadata. Misleading documentation can cause operators and automated systems to misunderstand what the tool does, weakening review quality and making inappropriate deployment or trust decisions more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Commands such as prioritize, remind, archive, and generic plan/add/report expand the tool beyond workout logging into a catch-all note-taking system. In skill ecosystems, unjustified extra capabilities are risky because they broaden the data the skill can solicit, store, and expose without matching the user's expected context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.