Hevy

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward read-only helper for using a Hevy fitness-data CLI, with normal cautions around API key handling and trusting the external CLI.

Install only if you trust the external hevycli project, prefer a pinned or reviewed version when possible, avoid pasting API keys into shared terminals or chats, and treat exported workout JSON files as private personal data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs users to set an API key directly on the command line but does not warn that command-line arguments may be exposed via shell history, process listings, terminal logs, or transcripts. Because the key grants access to personal fitness data, accidental exposure could allow unauthorized access to sensitive account information.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal