Samsung Health

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent for analyzing Samsung Health exports, with no evidence of deception or exfiltration, but it handles sensitive health data and installs a third-party Python CLI that users should review first.

Install only if you are comfortable letting a local CLI access Samsung Health backup data from the configured Google Drive account. Review the linked GitHub repository before running pip install, prefer a virtualenv or isolated machine, protect ~/.config/samsung-health/config.yaml and any downloaded Health Connect.zip files, and avoid using a Google account with broader Drive access than needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill handles highly sensitive health data and instructs users to download it from Google Drive, but it does not provide an explicit privacy warning or data-handling guidance. This can lead users to expose medical and biometric information without understanding the sensitivity, local storage implications, or risks of processing synced backups.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal