T03 · Remote Payload Retrieval and Execution
- Location
hevy/scripts/install_hevycli.sh:17- Finding
Unverified Remote Executable Download and Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent fitness and nutrition skill, but it needs review because it installs an unverified third-party executable, handles a Hevy API key insecurely, and makes persistent local data changes.
Review before installing. Use only if you are comfortable with a personal fitness skill writing to your vault, using Hevy data, and installing a third-party CLI. Prefer installing hevycli through a pinned and verified release, avoid passing API keys on the command line, set restrictive permissions on ~/.hevycli/config.yaml, and confirm before allowing the skill to create or update vault, character, or calendar files.
hevy/scripts/install_hevycli.sh:17Unverified Remote Executable Download and Installation
hevy/scripts/configure_api.sh:6Hevy API Key Exposed Through Process Arguments and Potentially Permissive File Permissions
hevy/scripts/install_hevycli.sh:8Predictable Shared Temporary Directory and Unrestricted Archive Extraction
Without declared permissions the skill's intent is opaque and cannot be validated.
The activation language is very broad and includes common topics like food, eating, exercise, and health, which can cause the skill to trigger on a wide range of ordinary conversation. Over-broad routing increases the chance of misclassification, unnecessary invocation of downstream sub-skills, and exposure of health/nutrition workflows in contexts where they were not intended.
The trigger phrases are extremely broad, covering common everyday food and eating language, which makes accidental activation likely during benign conversation. Because the skill has write-capable tools and file-modification behaviors, overbroad routing raises the risk that routine chat gets escalated into filesystem reads/writes without sufficiently specific user intent.
The skill is instructed to create and update multiple vault files automatically, but the user-facing behavior does not require a clear warning or consent before persistent modification. In a skill with broad triggers and write access, silent persistence can lead to unexpected data creation, overwrites, or privacy-sensitive logging the user did not knowingly authorize.
The skill expands beyond nutrition assistance into modifying RPG/character progression data, including awarding XP and updating character-related records. This violates least-privilege expectations for a food/nutrition skill and creates an unnecessary cross-domain write path that could be triggered during normal meal interactions, increasing the chance of unintended or unauthorized state changes.
The error-handling guidance allows the skill to initialize or modify character.md, which is unrelated to core meal logging or recipe management. Even if intended as convenience, it permits the nutrition skill to create or alter unrelated personal/game records, widening blast radius and enabling cross-file tampering from a loosely scoped trigger.
The activation text says to use the skill when the user mentions broad terms like workouts, running, sleep, soreness, or asks general questions such as 'how am I progressing'. This lacks clear scope boundaries or negative examples, so ordinary conversation about health or daily status could collide with the trigger and invoke the skill unintentionally.
The description says to use the skill when 'needing to track workouts, analyze exercise progress, get fitness statistics, create/manage routines, or query workout history,' which is a very broad natural-language trigger surface for a manifest/markdown description. It does not define narrower invocation constraints or exclusion conditions, so ordinary fitness or analytics requests could unintentionally route to this skill.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- **Command Reference:** `references/api_commands.md` - Complete CLI command guide
- **Data Structures:** `references/data_structures.md` - JSON schemas and examples
- **Hevy API Docs:** https://api.hevyapp.com/docs/
- **Hevy App:** https://www.hevyapp.com/
## Security Notes
This markdown file lists a workout deletion command, but provides no user warning that the operation is destructive or potentially irreversible. Under the markdown-file criteria for missing user warnings, commands that can affect user data should be accompanied by an explicit warning.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
mkdir -p "$TEMP_DIR"
# Get latest release URL
RELEASE_URL=$(curl -sL https://api.github.com/repos/obay/hevycli/releases/latest | grep "browser_download_url.*linux.*amd64" | cut -d '"' -f 4 | head -1)
if [ -z "$RELEASE_URL" ]; then
echo "❌ Failed to get download URL"
The script fetches a release URL from the GitHub API and immediately downloads and extracts a remote archive into a user-local binary directory without any integrity verification, signature checking, or pinning to a specific version. If the upstream repository, release asset, network path, or parsing logic is compromised, a malicious binary could be installed and later executed by the user.
The documentation explicitly shows setting an API key on the command line, which can expose sensitive credentials through shell history, process listings, terminal logging, or audit tooling. In an agent-oriented skill, this is more dangerous because automated systems may follow the example literally and persist secrets insecurely.
No suspicious patterns detected.