Back to skill

Security audit

fitness-assistant

Security checks across malware telemetry and agentic risk

Overview

This fitness skill is coherent and disclosed, but users should understand it may save sensitive health profile details and create a daily automation only when requested.

Before installing, be comfortable sharing and saving age, body metrics, health limitations, dietary restrictions, routine, timezone, and language in your OpenClaw profile. Only ask it to schedule daily plans if you want recurring messages, and review or remove the automation if your routine, timezone, or health situation changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
78% confidence
Finding
The invocation criteria are broad enough to capture many ordinary fitness or diet requests, causing the skill to collect sensitive health data and potentially trigger scheduling behavior in cases where a simpler response would suffice. In a health-related skill, over-broad triggering increases privacy and safety risk because users may be funneled into profiling and automated plan generation without sufficiently clear scope boundaries.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.