Back to skill

Security audit

Fitness

Security checks for vulnerabilities and agentic risk

Overview

The fitness skill is coherent, but it stores sensitive workout and health details in plaintext local files without an explicit opt-in, retention policy, or access-control guidance.

Before installing, be aware that this skill can create and reuse plaintext fitness records in your home directory, including injuries, heart-rate data, bodyweight, sleep, schedule constraints, and missed-session reasons. Use it only if you are comfortable with that local persistence, and consider restricting file permissions, avoiding cloud sync for the folder, and periodically reviewing or deleting stored records.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
setup.md:11
Finding

Persistent Plaintext Storage of Sensitive Fitness and Health Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · memory-template.md (reported line 15)May include surrounding context.

md
last: YYYY-MM-DD

## Baselines
<!-- Derived from log.md; recompute when they shift, keep the date -->
| Metric | Value | As of |
|---|---|---|
| e1RM squat | 120 kg | YYYY-MM-DD |

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the Fitness skill is for training-plan design and is 'Not for meal-level nutrition planning.' Line L03 states that calorie targets, macro math, and meal planning are part of this content flow, even if routed to another skill, which expands beyond the training-focused scope described in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template explicitly stores health- and fitness-related data such as injury history, resting heart rate, attendance, and training baselines in local files, but provides no warning about the sensitivity of that data or guidance on minimization, retention, or access control. Even though the storage is local, these files could be exposed through backups, sync tools, shared machines, or later agent actions, resulting in privacy leakage of sensitive personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the agent to read from and write to multiple user-local files containing sensitive health and profile data, but provides no user-facing notice, consent step, or transparency about persistence. Because this is a fitness skill, the data includes potentially sensitive health-related information such as injury history, resting heart rate, bodyweight, age, and exclusions, making silent collection and storage riskier than ordinary preference caching.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions direct persistent storage of user fitness, health, schedule, and wearable data across config, memory, and log files whenever such details are mentioned in normal conversation, without a strong necessity boundary or explicit opt-in. This creates unnecessary accumulation of sensitive longitudinal data, increasing privacy exposure and the chance of misuse, over-retention, or unintended reuse in later sessions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.