Back to skill

Security audit

Health Guardian

Security checks across malware telemetry and agentic risk

Overview

This health-monitoring skill appears purpose-aligned and not malicious, but it handles sensitive health data with recurring monitoring while under-disclosing privacy, consent, and reliability limits.

Review carefully before installing. Use only with explicit consent from the person whose health data is monitored, protect the local data directory, and understand that iCloud sync and any external alert channel can expose health information outside the machine. Treat it as an experimental helper, not a medical alert system, and test the import and analysis path before relying on alerts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill describes direct file read/write behavior against local health-export data and local storage files, but does not declare permissions. In a health-monitoring context, undeclared access to sensitive medical data reduces transparency and informed consent, making it easier for an agent or operator to expose or misuse private data without clear review.

Tp4

High
Category
MCP Tool Poisoning
Confidence
84% confidence
Finding
The skill claims broad proactive health monitoring and privacy guarantees, but the documented behavior centers on direct ingestion of local iCloud health exports, local parsing/storage, and alerting through channels like Telegram. This mismatch can mislead users about the real data flows, operational limits, and privacy exposure, which is especially dangerous because the processed data is highly sensitive medical information.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill processes sensitive medical data and explicitly supports external alert channels such as Telegram, yet it lacks a prominent warning about handling health information and possible transmission outside the local machine. In a chronic-care setting, users may assume stronger privacy guarantees than actually exist, increasing the risk of unauthorized disclosure of protected health details.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The package description advertises 'proactive health monitoring' and 'anomaly alerts' without any clear trigger boundaries, consent model, or activation constraints. In a health-related skill, ambiguous activation language is more dangerous because it can encourage overbroad data access, unsolicited monitoring behavior, or sensitive-health inferences beyond what a user explicitly requested.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.