Back to skill

Security audit

FitCheck: Workout Readiness & Recovery

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed browser-based biometric/emotion scanning guide, but users should treat its camera, microphone, upload, and sharing features as privacy-sensitive.

Before installing, understand that this skill points users to a third-party browser app for camera, microphone, uploaded photo/video, emotion, stress, composure, and heart-rate-estimate analysis. Use it only with informed consent, avoid uploading or sharing another person's media without permission, and treat exported summaries as sensitive even when raw video or audio is not shared.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The quick-start trigger phrases like "scan my face" and "read my composure" are broad natural-language commands that could be spoken in ordinary conversation or media playback and unintentionally invoke the skill. In this skill's context, unintended activation is more sensitive than usual because it leads users toward camera/microphone biometric analysis, making accidental launch of a privacy-sensitive workflow more risky.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The example command list contains multiple vague, everyday phrases such as "what's my heart rate?" and "analyze this photo" that are likely to overlap with normal user speech across many contexts. Because this skill performs or initiates highly sensitive biometric and emotional inference, ambiguous triggers increase the chance of unintended invocation, confusing consent boundaries and exposing users to privacy-invasive actions they did not mean to start.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation hints are broad and action-oriented, such as 'scan me' and 'read this video,' without clear consent, scope, or safety qualifiers. In a skill that processes highly sensitive biometric and affective inferences, broad activation language increases the chance of casual or non-consensual use and can normalize analysis of third parties without adequate friction.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill promotes sharing an 'emotional x-ray' and challenge-style comparison of scores before establishing a strong, upfront warning that the output is privacy-sensitive biometric or affective data. Because these summaries concern stress, authenticity, heart-rate estimates, and similar inferences, encouraging sharing can lead users to disclose sensitive personal data or pressure others into public comparison.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.