Muscle Gain
PassAudited by VirusTotal on May 12, 2026.
Overview
Type: OpenClaw Skill Name: muscle-gain Version: 1.0.0 The provided files consist solely of metadata (`_meta.json`) and skill documentation (`SKILL.md`). There is no executable code to analyze. The `SKILL.md` content describes a fitness tracking skill, detailing its purpose, usage, and metrics. It contains no instructions for the AI agent that could be interpreted as prompt injection, data exfiltration, malicious execution, or any other harmful behavior. The documentation explicitly states that 'All data stays local on your machine' and 'No cloud upload, no third-party access, full privacy', which indicates a lack of intent for data exfiltration.
Findings (0)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
A user could share sensitive body data or progress photos without knowing where that information will persist or whether it may be reused in later agent context.
The skill is designed to collect and organize sensitive personal fitness, nutrition, body-measurement, and photo data, but the artifacts do not define storage location, retention, deletion, or reuse boundaries.
Log body weight and measurements... monitor daily protein intake... Progress photos - Timestamped images with metadata
Use only with data you are comfortable storing in the agent environment, and require an explicit local storage location, deletion process, and retention policy before logging sensitive photos or measurements.
A user may trust the skill with sensitive health or body-photo data under a privacy guarantee that is not supported by the provided artifacts.
This is a strong privacy and encryption promise, but the reviewed artifacts indicate an instruction-only skill with no code or install mechanism to implement or verify local encrypted storage.
All data stays local on your machine - Your training logs, weight history, and progress photos are encrypted and stored offline. No cloud upload, no third-party access, full privacy.
Do not rely on the encryption/offline-storage claim unless the skill provides auditable storage code or clear instructions that keep data in a user-controlled encrypted local file.
