Back to skill

Security audit

Section 11: Endurance Training Coach (Intervals.icu)

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate endurance-coaching skill, but it relies on mutable remote instructions and understates some write and persistence capabilities.

Install only if you trust the CrankAddict/section-11 repository and are comfortable with an agent reading sensitive training data. Prefer local or vendored copies of protocol/templates, avoid mutable GitHub fallbacks where possible, use private repos and least-privilege credentials, keep heartbeat opt-in, and require explicit confirmation before any calendar, threshold, or annotation write.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill claims fetched content comes only from user-configured sources, yet it also instructs fetching protocol/templates from hardcoded GitHub raw URLs. This creates a trust-boundary mismatch and introduces supply-chain risk: remote content can change and influence agent behavior without being pinned, verified, or explicitly user-approved.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.