Cycling

Security checks across malware telemetry and agentic risk

Overview

This is a static cycling advice skill with no code execution or data access, though its caffeine advice should be treated cautiously.

Safe to install from an agentic-security perspective. Treat the training, bike-fit, nutrition, and caffeine recommendations as general advice rather than medical or professional coaching guidance, especially if you have health conditions, use medications, are pregnant, or are sensitive to stimulants.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill gives specific caffeine dosing guidance (3-6mg/kg before hard efforts) without any warning about contraindications, side effects, or user-specific risk factors such as heart conditions, pregnancy, anxiety, medication interactions, or stimulant sensitivity. In a fitness skill, users may treat this as actionable health advice and self-administer potentially unsafe amounts, increasing the chance of adverse effects like palpitations, hypertension, GI distress, or sleep disruption.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal