Back to skill

Security audit

Apple Health Sync

Security checks across malware telemetry and agentic risk

Overview

The skill handles sensitive Apple Health data, but its file, network, key, and device-unlink behavior is disclosed, scoped, and aligned with its stated sync purpose.

Install only if you want this agent to manage Apple Health sync data. Treat the local state directory and any saved summaries as sensitive health information, review the fixed Supabase relay endpoints, and confirm automation or report-saving requests only when you intended them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding
The skill performs sensitive operations including shell execution, local file reads/writes, and outbound network access, but does not declare explicit permissions for those capabilities in a machine-enforceable way. This creates a governance gap: an agent platform or reviewer may under-estimate the skill's access, allowing execution in contexts where users did not clearly consent to filesystem, command, or network activity involving health data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/config.md:55