Back to skill

Security audit

Wyze Scale

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed health-data assistant that needs a Gevety API token, so it is sensitive but purpose-aligned.

Install only if you intend your agent to access your Gevety health account. Use it in private conversations, protect the Gevety API token, and revoke or rotate the token if you no longer want the skill to access your health data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill advertises very broad natural-language triggers such as questions about weight, BMI, body fat, and trends without strong trigger constraints or explicit privacy gating. In this context, the skill exposes highly sensitive health data and even supports multiple household members, so broad activation phrasing increases the chance of accidental invocation, mis-scoping to the wrong person, or disclosure in the wrong conversation context.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.