Back to skill

Security audit

Apple Health Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and not malicious, but it sends sensitive Apple Health and coaching data through a third-party API without enough privacy, retention, or scoping detail.

Review Transition's privacy policy and account controls before installing. Only use this skill if you are comfortable sending Apple Health-derived workouts, performance metrics, profile data, chat prompts, and possibly chat history to Transition's service; protect the API key and revoke it if access is no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 12)May include surrounding context.

Try it right now — no API key needed:

bash
curl "https://api.transition.fun/api/v1/wod?sport=run&duration=45"

For personalized features (your Apple Health data, training plan, AI coach), you need a Transition account + API key. See Getting an API Key below.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 12)May include surrounding context.

Try it right now — no API key needed:

bash
curl "https://api.transition.fun/api/v1/wod?sport=run&duration=45"

For personalized features (your Apple Health data, training plan, AI coach), you need a Transition account + API key. See Getting an API Key below.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

Try it right now — no API key needed:

bash
curl "https://api.transition.fun/api/v1/wod?sport=run&duration=45"

For personalized features (your Apple Health data, training plan, AI coach), you need a Transition account + API key. See Getting an API Key below.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly tells users that personalized features use their Apple Health data via a remote Transition account/API, but it does not provide any meaningful warning about privacy, retention, sharing, or data-handling practices. Because Apple Health data is sensitive medical/fitness information, encouraging transmission to a third-party service without clear disclosure creates a real privacy/security risk even if the behavior is intentional product functionality.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This example instructs users to send API-authenticated requests containing potentially sensitive Apple Health-derived questions to a third-party AI coaching endpoint. In the context of a health-data skill, remote transmission of authenticated, potentially medical/fitness-related content without prominent privacy/security disclosure materially increases risk of unintended exposure, logging, or secondary use.

Content

Scanner excerpt · README.md (reported line 55)May include surrounding context.

md
curl -X POST -H "X-API-Key: $TRANSITION_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"message": "How has my resting heart rate changed over the last month?"}' \
  "https://api.transition.fun/api/v1/coach/chat"

# Get your fitness/fatigue/form metrics
curl -H "X-API-Key: $TRANSITION_API_KEY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This example directs users to retrieve performance metrics from a remote API using an API key, implying transmission and processing of personal fitness/health analytics by an external service. In a skill centered on Apple Health data, such remote handling is security-relevant and should be clearly disclosed because the data is sensitive and may reveal health conditions or activity patterns.

Content

Scanner excerpt · README.md (reported line 59)May include surrounding context.

Get your fitness/fatigue/form metrics

curl -H "X-API-Key: $TRANSITION_API_KEY"
"https://api.transition.fun/api/v1/performance/pmc"

text

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly handles highly sensitive health data and instructs users to generate and use an API key, but it does not provide an explicit warning that user health data and prompts are transmitted to a third-party service. In a health-data context, missing disclosure and privacy guidance increases the risk of users unintentionally exposing regulated or sensitive personal information.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

Generate a random structured workout — no account needed.

bash
curl "https://api.transition.fun/api/v1/wod?sport=run&duration=45"

Parameters:

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This endpoint sends a natural-language message about the user's Apple Health data to a third-party AI coaching service using an API key. Because the skill states the AI coach has full context on workouts and health metrics, this is a real external transmission of sensitive health information, and the health-data context makes it more dangerous than ordinary API usage.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

curl -X POST -H "X-API-Key: $TRANSITION_API_KEY"
-H "Content-Type: application/json"
-d '{"message": "How has my resting heart rate changed over the last month?"}'
"https://api.transition.fun/api/v1/coach/chat"

text

Example questions:

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The workouts endpoint transmits authenticated requests to a third-party service that exposes the user's workout schedule/history, which is sensitive behavioral and health-adjacent data. In this skill's context, external transmission is intrinsic to the feature, but it still represents a genuine privacy/security risk if users are not clearly informed and protected.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

bash
curl -H "X-API-Key: $TRANSITION_API_KEY" \
  "https://api.transition.fun/api/v1/workouts?start=2026-02-09&end=2026-02-15"

Parameters:

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The PMC endpoint exposes derived fitness/fatigue metrics from Apple Health workout data to an external service. Although expected for the product, these metrics reveal sensitive health and performance characteristics, so the transmission should be treated as a real privacy-relevant vulnerability in the absence of strong disclosure and safeguards.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

bash
curl -H "X-API-Key: $TRANSITION_API_KEY" \
  "https://api.transition.fun/api/v1/performance/pmc"

Performance Stats

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The performance stats endpoint returns derived physiological/performance information such as FTP, threshold paces, and heart rate zones through a third-party API. These are sensitive fitness/health indicators, and transmitting them externally without prominent privacy framing increases user exposure.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
curl -H "X-API-Key: $TRANSITION_API_KEY" \
  "https://api.transition.fun/api/v1/performance/stats"

Athlete Profile

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The athlete profile endpoint likely exposes consolidated personal and health-related profile information through a third-party service. Profile-level aggregation raises sensitivity because it can facilitate user identification and broad inference about health, training, and habits.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

bash
curl -H "X-API-Key: $TRANSITION_API_KEY" \
  "https://api.transition.fun/api/v1/profile"

Chat History

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The chat history endpoint suggests that prior AI conversations about Apple Health data are stored and retrievable from the external service. Stored conversational history can contain highly sensitive health details and longitudinal behavioral information, making this particularly risky without explicit retention and deletion disclosures.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

bash
curl -H "X-API-Key: $TRANSITION_API_KEY" \
  "https://api.transition.fun/api/v1/coach/history"

Rate Limits

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description frames the skill as an interface for asking questions about a user's Apple Health data, workouts, heart rate, activity rings, and fitness trends. However, the documentation also exposes a 'Workout of the Day' endpoint that generates random structured workouts without needing account access, which goes beyond health-data conversation into workout creation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.