Back to skill

Security audit

Exist

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate Exist health-data integration, but its broad activation and confirmation-free reads of sensitive personal data should receive human review.

Install only if you want the agent to access your Exist health and lifestyle data. Before use, prefer explicit prompts that name the Exist data you want retrieved, and treat reads of profile, attributes, correlations, and insights as sensitive even when the skill labels them safe.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description is broadly phrased to activate on generic health, fitness, and lifestyle analysis requests without clear limits on when the skill should be invoked. Because this skill exposes highly sensitive health data, over-broad routing increases the chance of unnecessary access, disclosure, or analysis of private user information in situations where the tool is not strictly required.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
## Security & Permissions

- **Read** tools are safe and require no confirmation
- **Write** tools (acquire/increment/release ownership) require confirmation
- Releasing ownership is high-impact and stops data flow for that attribute
Confidence
82% confidence
Finding
Labeling all read tools as 'safe' and requiring no confirmation is risky in a health-data skill because read operations can expose sensitive wellness, behavioral, and correlation data. Even without modifying data, autonomous retrieval of profile details, tracked attributes, or AI-generated insights can disclose private information beyond what the user intended to reveal.

Static analysis

No suspicious patterns detected.