Back to skill

Security audit

Gym

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only gym coaching skill with disclosed local tracking, but users should be aware it may store sensitive fitness and injury details on disk.

Before installing, understand that this skill may keep workout logs, body measurements, weight trends, schedule, goals, and injury restrictions in plaintext files under ~/gym. Use it only if you are comfortable with that local retention, review or delete those files when needed, and treat injury, supplement, and nutrition guidance as general fitness information rather than medical advice.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:21
Finding

Plaintext Persistence of Sensitive Health and Fitness Data Without Access-Control Requirements

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:21-49; progress.md:93-105
Vulnerability Type: Plaintext sensitive-data storage with unspecified filesystem permissions
Risk Level: Medium

Relevant snippet from SKILL.md:

markdown
User preferences persist in `~/gym/memory.md`. Create on first use:

```markdown
## Level
<!-- beginner | intermediate | advanced -->

## Goals
<!-- strength | hypertrophy | fat-loss | general-fitness | powerlifting -->

## Schedule
<!-- Days available. Format: "days | frequency" -->
<!-- Examples: Mon/Wed/Fri, 3x/week, daily -->

## Session Duration
<!-- 45min | 60min | 90min -->

## Restrictions
<!-- Injuries, equipment limits, mobility issues -->
<!-- Examples: Lower back injury (no deadlifts), Home gym (no cable machine) -->

Fill on first conversation. Update as goals evolve.

Data Storage

Store workout logs and measurements in ~/gym/:

  • workouts — Session logs (date, exercises, sets, reps, weight)
  • prs — Personal records by exercise
  • measurements — Body measurements, weight trends
text

**Relevant snippet from `progress.md`:**

```markdown
Store in `~/gym/measurements.md`:

2024-01-01

  • Weight: 82.5kg (morning, fasted)
  • Chest: 102cm
  • Waist: 84cm
  • Hips: 98cm
  • Arms: 38cm
  • Thighs: 60cm

Notes

  • Measure same time, same conditions
text

### Technical Analysis

The Skill explicitly directs the agent to persist injury restrictions, body measurements, weight trends, workout history, and personal records in Markdown files under `~/gym`. These records may constitute sensitive health and fitness information.

The storage instructions do not require the agent to:

- Create `~/gym` with owner-only permissions.
- Create data files with a restrictive mode such as `0600`.
- Check whether existing files are symbolic links or owned by another user.
- Obtain consent
...[truncated 2002 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit user consent before persisting injury details, body measurements, or other sensitive information.
  2. Create ~/gym with owner-only permissions, such as mode 0700, and verify its ownership before use.
  3. Create all data files with mode 0600; do not rely solely on the process umask.
  4. Use safe file-creation semantics that reject symbolic links and avoid overwriting files owned by another principal.
  5. Store only the minimum information required for the requested functionality. Avoid retaining detailed medical information when a less-sensitive restriction is sufficient.
  6. Clearly disclose which fields are retained, where they are stored, and how long they remain available.
  7. Provide commands or documented procedures to inspect, export, redact, and permanently delete retained records.
  8. Consider encryption at rest using an operating-system credential store or user-controlled encryption key when sensitive records must persist.
  9. Apply retention limits and remove stale measurements, injury notes, and workout history unless the user opts into longer retention.
  10. Avoid writing sensitive values to diagnostic logs, temporary files, or broadly accessible backup and synchronization locations.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly persists sensitive health-adjacent data such as fitness level, goals, schedule, restrictions, workout logs, PRs, and body measurements in a local user directory without any privacy notice, consent flow, retention policy, or deletion guidance. Even if stored locally, this creates privacy risk because the data can reveal medical limitations, habits, and physical condition, and users are not clearly informed that this information will be retained across sessions and updates.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file provides specific injury-related exercise restrictions, substitutions, rehabilitation phases, and return-to-training timelines without a clear warning to consult a qualified clinician or physical therapist. Because the guidance targets users with medical or musculoskeletal issues, readers may self-treat based on generalized advice that is inappropriate for their condition, potentially worsening injury or delaying proper care.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This section gives concrete supplement dosages such as caffeine at 3-6mg/kg and vitamin D at 1000-2000 IU without any warning that medical conditions, medications, pregnancy, age, stimulant sensitivity, or existing deficiencies can change what is safe. In a fitness coaching skill, users may treat the guidance as personalized health advice, which increases the risk of adverse effects such as excessive stimulant intake or inappropriate supplementation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file provides detailed exercise programming, loading schemes, and substitutions without any safety disclaimer, screening guidance, or instruction to adapt plans for injuries, medical conditions, mobility limitations, or novice technique constraints. In a fitness coaching context, users may follow the routines directly and attempt movements like squats, deadlifts, weighted pull-ups, or under-desk inverted rows in ways that increase risk of strain, falls, or aggravation of existing conditions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.