Back to skill

Security audit

Body

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent fitness and nutrition skill, but it needs review because it installs an unverified third-party executable, handles a Hevy API key insecurely, and makes persistent local data changes.

Review before installing. Use only if you are comfortable with a personal fitness skill writing to your vault, using Hevy data, and installing a third-party CLI. Prefer installing hevycli through a pinned and verified release, avoid passing API keys on the command line, set restrictive permissions on ~/.hevycli/config.yaml, and confirm before allowing the skill to create or update vault, character, or calendar files.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
hevy/scripts/install_hevycli.sh:17
Finding

Unverified Remote Executable Download and Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
hevy/scripts/configure_api.sh:6
Finding

Hevy API Key Exposed Through Process Arguments and Potentially Permissive File Permissions

Content
View full analysis
" echo "💡 Get your API key from: https://hevy.com/settings?developer" exit 1 fi echo "🔧 Configuring hevycli..." # Create config directory mkdir -p "$CONFIG_DIR" # Create config file cat > "$CONFIG_FILE" << EOF api: key: "$API_KEY" display: output_format: json color: false units: metric EOF ``` The documented invocation explicitly places the secret on the command line: ```bash ./scripts/configure_api.sh YOUR_API_KEY ``` ### Technical Analysis The API key is accepted as positional argument `$1`. Command-line secrets may be retained in shell history and may be observable through process-inspection facilities while the command runs. They can also be captured by terminal logging, command auditing, wrapper scripts, or diagnostic tooling. The script then stores the key in plaintext at `~/.hevycli/config.yaml`. Although `hevy/SKILL.md` states that the file should have mode `600`, the script neither sets `umask 077` nor applies `chmod 600`. Consequently, the resulting mode depends on the caller's current `umask`. Under a common `022` umask, a newly created file may be mode `0644`, making the credential readable by other local users. The configuration directory is likewise created without explicitly enforcing mode `0700`. ### Attack Path 1. A user follows the documented command and supplies the Hevy key as a positional argument. 2. The command, including the secret, may be saved in shell history or exposed to local process/audit inspection. 3. The script creates `~/.hevycli/config.yaml` using the caller's existing `umask`. ...[truncated 956 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
hevy/scripts/install_hevycli.sh:8
Finding

Predictable Shared Temporary Directory and Unrestricted Archive Extraction

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation language is very broad and includes common topics like food, eating, exercise, and health, which can cause the skill to trigger on a wide range of ordinary conversation. Over-broad routing increases the chance of misclassification, unnecessary invocation of downstream sub-skills, and exposure of health/nutrition workflows in contexts where they were not intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are extremely broad, covering common everyday food and eating language, which makes accidental activation likely during benign conversation. Because the skill has write-capable tools and file-modification behaviors, overbroad routing raises the risk that routine chat gets escalated into filesystem reads/writes without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is instructed to create and update multiple vault files automatically, but the user-facing behavior does not require a clear warning or consent before persistent modification. In a skill with broad triggers and write access, silent persistence can lead to unexpected data creation, overwrites, or privacy-sensitive logging the user did not knowingly authorize.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill expands beyond nutrition assistance into modifying RPG/character progression data, including awarding XP and updating character-related records. This violates least-privilege expectations for a food/nutrition skill and creates an unnecessary cross-domain write path that could be triggered during normal meal interactions, increasing the chance of unintended or unauthorized state changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The error-handling guidance allows the skill to initialize or modify character.md, which is unrelated to core meal logging or recipe management. Even if intended as convenience, it permits the nutrition skill to create or alter unrelated personal/game records, widening blast radius and enabling cross-file tampering from a loosely scoped trigger.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation text says to use the skill when the user mentions broad terms like workouts, running, sleep, soreness, or asks general questions such as 'how am I progressing'. This lacks clear scope boundaries or negative examples, so ordinary conversation about health or daily status could collide with the trigger and invoke the skill unintentionally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description says to use the skill when 'needing to track workouts, analyze exercise progress, get fitness statistics, create/manage routines, or query workout history,' which is a very broad natural-language trigger surface for a manifest/markdown description. It does not define narrower invocation constraints or exclusion conditions, so ordinary fitness or analytics requests could unintentionally route to this skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · hevy/SKILL.md (reported line 226)May include surrounding context.

md
- **Command Reference:** `references/api_commands.md` - Complete CLI command guide
- **Data Structures:** `references/data_structures.md` - JSON schemas and examples
- **Hevy API Docs:** https://api.hevyapp.com/docs/
- **Hevy App:** https://www.hevyapp.com/

## Security Notes

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file lists a workout deletion command, but provides no user warning that the operation is destructive or potentially irreversible. Under the markdown-file criteria for missing user warnings, commands that can affect user data should be accompanied by an explicit warning.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · hevy/scripts/install_hevycli.sh (reported line 17)May include surrounding context.

sh
mkdir -p "$TEMP_DIR"

# Get latest release URL
RELEASE_URL=$(curl -sL https://api.github.com/repos/obay/hevycli/releases/latest | grep "browser_download_url.*linux.*amd64" | cut -d '"' -f 4 | head -1)

if [ -z "$RELEASE_URL" ]; then
    echo "❌ Failed to get download URL"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script fetches a release URL from the GitHub API and immediately downloads and extracts a remote archive into a user-local binary directory without any integrity verification, signature checking, or pinning to a specific version. If the upstream repository, release asset, network path, or parsing logic is compromised, a malicious binary could be installed and later executed by the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly shows setting an API key on the command line, which can expose sensitive credentials through shell history, process listings, terminal logging, or audit tooling. In an agent-oriented skill, this is more dangerous because automated systems may follow the example literally and persist secrets insecurely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.