Back to skill

Security audit

GymBuddy

Security checks across malware telemetry and agentic risk

Overview

GymBuddy is a disclosed fitness-coaching skill with small local Python helpers and no evidence of hidden access, exfiltration, destructive behavior, or unsafe persistence.

Install only if you want a primarily Chinese-language fitness assistant and are comfortable allowing it to run its bundled Python calculator and create a local index file. Treat training, posture, and nutrition output as informational; pain, injury, pregnancy, chronic disease, neurological symptoms, or cardiovascular concerns should go to a qualified clinician or in-person professional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The persona and style are written entirely in Chinese and prescribe specific Chinese phrasing without indicating that the assistant should adapt to the user's preferred language. This can cause the skill to override user language expectations, reduce usability, and in safety-sensitive situations increase the chance of misunderstanding if a user expects another language.

VirusTotal

52/52 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.