Back to skill

Security audit

Cn Weight Tracker

Security checks for vulnerabilities and agentic risk

Overview

This is a narrow Chinese weight-tracking skill that stores health measurements locally, with privacy caveats but no hidden execution, exfiltration, or destructive behavior found.

Install only if you are comfortable storing weight, height, target, and dated weight records as plaintext JSON on the local account. Prefer a trusted personal device and avoid shared accounts; consider tightening file permissions or deleting the data file when no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
scripts/weight_tracker.py:7
Finding

Health Data Stored in Plaintext Without Enforced Access Restrictions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill documents file read/write behavior via a local JSON store but does not declare any explicit tool scope or permissions. This creates a transparency and least-privilege problem: an agent or reviewer cannot easily verify what filesystem access is intended, increasing the risk of overbroad file operations or unexpected access beyond the weight data file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill name, examples, and command phrases are entirely in Chinese, and the usage section only demonstrates Chinese-language inputs such as "记录体重" and "算BMI". There is no indication that this is an opt-in locale-specific skill or that users can choose another language, which may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Broad trigger phrases such as everyday natural-language inputs can cause accidental activation or misrouting, especially in shared assistant contexts. Because this skill performs file writes to persistent local storage, unintended invocation could silently create or modify personal health records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill persists health-related data such as weight, height, targets, and dated records to a predictable local file under the user's home directory without any disclosure, consent flow, or protection checks. Health data is sensitive personal information, and storing it silently increases privacy risk if the host is shared, backed up, or otherwise accessed by other local processes or users.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill is presented as a local-only weight tracker with '数据完全本地存储,隐私无忧' at L61, implying a narrowly scoped, privacy-focused tool. However, the same manifest advertises an external website and diagnostic page at L65-L66, which expands the skill's apparent scope beyond weight tracking and weakens the claimed local-only framing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

User-facing strings, examples, and command triggers are entirely in Chinese, and the skill name also indicates a Chinese locale. The file does not state that the skill is region-specific or provide any opt-in or alternative language handling, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.