Back to skill

Security audit

Health Guardian

Security checks across malware telemetry and agentic risk

Overview

This skill is purpose-aligned health monitoring, but it handles very sensitive health data with weak scoping, misleading privacy wording, and ongoing automation guidance.

Install only after the person whose health data is involved has explicitly consented. Before enabling cron or alerts, verify the real import directory, protect or periodically delete the local data files, avoid Telegram or other external notifications unless message contents and recipients are tightly controlled, and do not rely on this skill for medical safety without fixing the importer/analyzer storage mismatch.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill documents direct reading from a local iCloud health export path and writing persistent health data files, but it does not declare corresponding permissions or boundaries. In a health-monitoring context, undeclared file access is risky because it handles highly sensitive medical data and prevents users or hosting agents from making informed trust decisions about local data exposure.

Tp4

High
Category
MCP Tool Poisoning
Confidence
81% confidence
Finding
The documented behavior goes beyond a simple monitoring description by accessing local iCloud-exported health files, processing archives, and persisting merged health records locally. That mismatch matters because users may authorize a benign-sounding monitoring skill without realizing it performs broad ingestion and storage of sensitive health data, increasing privacy and misuse risk.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This skill handles protected health information and explicitly supports alerting via external channels such as Telegram, yet it lacks a prominent warning about sensitive data handling, third-party notification exposure, and consent requirements. In this context, omission is dangerous because health alerts can disclose medical conditions, routines, or anomalies to unintended parties or insecure services.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The script processes highly sensitive health data from a local JSON file without any explicit privacy notice, consent check, or guidance about secure handling. In a health-monitoring skill intended for agents caring for humans with chronic conditions, silent processing of personal medical information increases privacy and compliance risk because users or operators may not realize protected health data is being accessed and summarized.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.