Back to skill

Security audit

Running Coach

Security checks for vulnerabilities and agentic risk

Overview

This running-coach skill is purpose-aligned and disclosed, but users should handle the Intervals.icu API key carefully and understand that running the upload script changes their training calendar.

Install only if you are comfortable giving the skill access to your Intervals.icu account for workout-plan creation. Prefer environment variables for the API key, do not commit a populated config.json, use --dry-run before uploading, and rotate the API key if it is ever exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
config.json:4
Finding

Plaintext API Credential Storage Without File-Permission Safeguards

Content
View full analysis
` for HTTP Basic authentication and transmits it over HTTPS to the fixed `https://intervals.icu/api/v1` endpoint. Base64 is not encryption, but its use here is required by the authentication protocol and does not constitute a covert exfiltration channel based on the reviewed implementation. ### Attack Path 1. A user places a valid Intervals.icu API key in `config. ...[truncated 1373 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

md
| 创建训练 | `POST /api/v1/athlete/{id}/events?upsertOnUid=true` |
| 批量创建 | `POST /api/v1/athlete/{id}/events/bulk?upsertOnUid=true` |
| 更新训练 | `PUT /api/v1/athlete/{id}/events/{event_id}` |
| 删除训练 | `DELETE /api/v1/athlete/{id}/events/{event_id}` |
| 获取活动 | `GET /api/v1/athlete/{id}/activities?oldest=&newest=` |
| 获取计划 | `GET /api/v1/athlete/{id}/events?oldest=&newest=` |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to place an API key in environment variables or a config.json file, but gives no guidance on protecting that secret from shell history, source control, shared machines, or accidental disclosure. Because the same credential enables authenticated access to Intervals.icu, exposure could let another party read or modify the user's training data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documented API endpoints include create, bulk create, update, and delete operations that can alter or remove user training plans, but the skill does not warn users that these are state-changing actions. In an agent context, lack of confirmation and impact warnings increases the chance of accidental destructive changes or misuse with the provided credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language description, author-facing labels, tags, and environment variable descriptions are presented only in Chinese, which indicates a language-specific skill experience without any opt-in or alternative locale. Under the policy for natural-language violations, forcing a specific language without user choice should be flagged unless the locale restriction is clearly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script transmits workout data to the external Intervals.icu API as part of normal operation, but it does not provide a clear explicit warning or confirmation at the point of upload. In a skill/agent context, silent off-system transmission can surprise users, cause unintended disclosure of schedule/training metadata, and create consent and privacy issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template presents all user-facing content in Chinese and does not indicate that the user can select another language or that the template is intended only for a Chinese-speaking context. Under the policy rule for natural-language constraints, forcing a specific language without opt-in is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown template presents all user-facing headings and instructions in a single language, which can amount to a language/locale policy issue when no opt-in or justification is provided. The file does not indicate that the skill is intended only for Chinese-speaking users or provide an alternative language option.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The top-level documentation claims the weekly plan is automatically generated based on a specific training methodology. In practice, generate_weekly_plan returns a static list of preset workouts with only dates and pace-reference text adjusted, so the comment overstates what the code actually does.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Natural-language strings in the module description, comments, CLI help, and status messages are Chinese-only, and the file does not indicate that this locale restriction is intentional or optional. Per the policy, forcing a specific language without user opt-in can be a language/locale policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.