Back to skill

Security audit

HealthKit Sync

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for using a local HealthKit sync CLI, with sensitive health-data handling that is expected for its purpose but should be used carefully.

Install only if you use the healthsync CLI and are comfortable handling Apple Health data locally. Treat exported CSV or JSON files as sensitive: store the minimum needed, avoid shared or cloud-synced folders when possible, and delete exports when finished.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document presents an inconsistent security model by claiming token theft is mitigated by Keychain storage, while later stating iOS server tokens are stored as SHA256 hashes in SwiftData instead. This can lead implementers, reviewers, or operators to make incorrect assumptions about where sensitive authentication material is protected, weakening operational controls and incident response.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill provides commands to export highly sensitive health data such as heart rate, sleep, and body metrics directly to local files, but it does not warn about privacy risks, retention, file permissions, backups, or downstream sharing. Because this data is medical-adjacent and often protected by policy or regulation, omission of handling guidance increases the chance users will create exposed plaintext artifacts on disk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The testing guide states that the skill activates on 'relevant keywords' without defining tight scope or exclusion criteria. In an agent setting, ambiguous activation guidance can cause the skill to trigger in unrelated conversations, increasing the chance that health-data, device-pairing, or security-architecture instructions are surfaced when not intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The keyword list includes broad terms such as 'iPhone', 'iOS', 'macOS', 'sync', and 'fetch', which are common across many benign contexts. Without exclusion conditions, this can lead to overbroad invocation and unintentional disclosure of operational details, file paths, or security implementation specifics to prompts that only loosely match the domain.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.