Back to skill

Security audit

Fat Loss Coach

Security checks for vulnerabilities and agentic risk

Overview

This fat-loss coaching skill is not malicious, but it automatically records sensitive health/body data and gives diet and exercise guidance without enough consent, privacy, or medical-safety guardrails.

Install only if you are comfortable with the agent storing sensitive weight, body measurements, diet, exercise, and health-condition notes in local memory. Ask for explicit confirmation before saving profiles, avoid entering detailed medical history unless needed, and treat meal, fasting, and workout plans as general guidance that should be checked with a clinician or qualified dietitian/trainer if you have medical conditions, pregnancy, injury, eating-disorder history, diabetes, or are a minor.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:172
Finding

Unprotected Persistent Storage of Sensitive Health Profiles

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 172-205
Vulnerability Type: Plaintext storage of sensitive personal and health information
Risk Level: Medium

The documented workflow instructs the Agent to persist each user's demographic, health, and progress information in a Markdown file:

markdown
Output recommendations
    ↓
Record them in the user profile (memory/user-ID/fat-loss-profile.md)
markdown
Each user's data is stored in `memory/{user-id}/fat-loss-profile.md` and includes:

# Fat-Loss Profile

## Basic Information
- Gender:
- Age:
- Height:
- Initial weight:
- Target weight:
- Activity level:
- Dietary preferences:
- Health conditions:

## Calculation Results
- BMR:
- TDEE:
- Target calories:

## Progress Records
| Date | Weight | Body-fat percentage | Waist | Exercise | Diet score | Notes |
|------|--------|---------------------|-------|----------|------------|-------|

Technical Analysis

The workflow stores health conditions, body measurements, dietary preferences, and behavioral records in a predictable plaintext path. It does not require:

  • Explicit user consent before persistence
  • Data minimization
  • Retention or automatic deletion limits
  • File access restrictions
  • Encryption at rest
  • Separation between different users
  • Validation or canonicalization of {user-id} before path construction

If the runtime directly interpolates a user-controlled identifier into the documented path, path separators or traversal sequences could cause the profile to be written outside the intended user directory. Even without path traversal, predictable plaintext profile files can expose sensitive information to other processes or users that can read the Agent's storage directory.

No profile-writing implementation is present in scripts/calculate.py; exploitation therefore depends on the host Agent following the documented storage workf ...[truncated 1083 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make profile persistence opt-in and clearly disclose which fields will be stored.
  2. Store only information required for the current coaching function; avoid retaining free-form health notes by default.
  3. Replace user-provided path components with server-generated opaque identifiers.
  4. Reject path separators, traversal sequences, absolute paths, null bytes, and unexpected identifier characters.
  5. Resolve and canonicalize the destination path, then verify that it remains beneath the designated profile directory before writing.
  6. Apply restrictive file permissions so profiles are accessible only to the Agent's service account.
  7. Encrypt sensitive records at rest when the host environment supports it.
  8. Define retention periods and provide profile inspection, export, and deletion controls.
  9. Separate users at the storage and authorization layers rather than relying only on directory naming.
  10. Avoid writing profiles when the runtime cannot provide appropriate privacy and access-control guarantees.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/calculate.py:72
Finding

Unvalidated Numeric Inputs Can Produce Unsafe Calorie and Macronutrient Results

Content
View full analysis

Vulnerability Details

File Location: scripts/calculate.py, lines 72-97
Vulnerability Type: Missing input validation and failure to enforce documented safety limits
Risk Level: Medium

The target calculation subtracts an unrestricted deficit, while all numeric inputs are converted without finite-value, domain, or plausible-range validation:

python
def calculate_target(tdee, deficit=400):
    """
    Calculate the fat-loss calorie target.

    Args:
        tdee: Total daily energy expenditure
        deficit: Calorie deficit, defaulting to 400 kcal

    Returns:
        Target calories
    """
    return round(tdee - deficit, 1)
python
# Parse input
gender = data.get('gender', 'male')
weight = float(data.get('weight', 70))
height = float(data.get('height', 170))
age = int(data.get('age', 30))
activity = float(data.get('activity', 1.375))
deficit = float(data.get('deficit', 400))

The resulting target is subsequently used to calculate macronutrients:

python
bmr = calculate_bmr(gender, weight, height, age)
tdee = calculate_tdee(bmr, activity)
target = calculate_target(tdee, deficit)
macros = calculate_macros(target, weight)

Technical Analysis

The script accepts negative, zero, extreme, and non-finite floating-point inputs. It does not enforce the calorie floors documented elsewhere in the project: 1,500 kcal per day for men and 1,200 kcal per day for women.

A sufficiently large deficit, negative weight, negative activity factor, or otherwise invalid value can produce a negative calorie target. calculate_macros then allocates remaining calories to carbohydrates, potentially returning negative carbohydrate calories and grams.

Gender is also insufficiently validated: every value other than a case-insensitive exact match for male silently uses the female formula. Activity is accepted as an unrestricted floating-point coefficient rather than one o ...[truncated 1398 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require the top-level JSON value to be an object before accessing fields.
  2. Validate gender against an explicit supported enumeration and reject unknown values.
  3. Restrict activity to documented coefficients or map named activity levels to trusted coefficients.
  4. Use math.isfinite for every numeric value.
  5. Enforce positive and physiologically plausible ranges for weight, height, and age.
  6. Restrict the deficit to a documented safe range, such as 300-500 kcal by default, with controlled exceptions.
  7. Enforce the documented minimum calorie target for the selected population rather than merely describing it in documentation.
  8. Reject calculations where calories remaining for carbohydrates are negative.
  9. Catch TypeError, ValueError, OverflowError, and arithmetic failures, then return a structured validation error without a traceback.
  10. Add boundary tests covering negative numbers, zero, extreme values, booleans, null values, unsupported gender values, NaN, and infinity.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个覆盖减脂全流程的智能助手,但提供的代码片段实际只是一个热量与宏量营养计算器。它能够完成声明中的一部分,即基础代谢、TDEE、目标热量和宏量营养素计算;但没有看到任何与个性化饮食计划生成、运动规划、进度记录/追踪、根据进展调整建议或问答交互相关的实现。代码也没有访问额外资源或执行未声明的敏感能力,因此问题主要是声明范围明显大于实际功能,属于描述与实际行为不一致。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs storing sensitive health-related and body metrics data in per-user memory files, including age, weight, health status, and progress history, without any notice, consent flow, retention policy, or privacy safeguards. This creates privacy and compliance risk because users may not realize their sensitive data is being persisted and such data could be exposed, retained longer than expected, or accessed by other components.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file provides broad dietary and weight-loss guidance with quantitative claims and behavioral recommendations, but it does not warn that the content is general information rather than individualized medical or nutritional advice. In a fat-loss coaching skill, users may rely on these recommendations despite allergies, diabetes, eating disorders, pregnancy, kidney disease, medication interactions, or other conditions, increasing the risk of unsafe dieting or inappropriate food choices.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file provides prescriptive weight-loss meal plans, including a 1200 kcal 'female fat-loss lower limit' plan, without any screening, medical disclaimer, or guidance to seek professional advice for users with health conditions, pregnancy, eating disorders, diabetes, or adolescent age. In the context of a fat-loss coaching skill, users may treat these templates as authoritative recommendations, which increases the risk of unsafe caloric restriction or inappropriate diet choices for vulnerable individuals.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file provides actionable weight-loss adjustment and fasting guidance, including calorie reductions and a 16:8 fasting protocol, but does not clearly warn that this is not medical advice or direct users with relevant conditions to a qualified clinician before making safety-critical changes. In a health-coaching skill, users may rely on this guidance for real behavior changes, which increases the risk of harm for people with diabetes, pregnancy, eating-disorder history, medication interactions, or other medical vulnerabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file gives prescriptive exercise routines ranging from beginner walking through HIIT, heavy lifting patterns, and heart-rate-based intensity targets, but it does not warn users to assess their health status, contraindications, injuries, age, pregnancy status, or chronic conditions before starting. In a fat-loss coaching skill, users may treat this as actionable health guidance; without screening or a recommendation to consult a clinician or qualified trainer, the plan can contribute to overexertion, aggravation of musculoskeletal issues, or cardiovascular events in at-risk users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This Python file contains user-facing natural-language content entirely in Chinese, including the skill title and function/docstring descriptions, without offering a language choice or explaining that the skill is intended only for a Chinese-speaking context. Under the policy rule for natural-language violations, this is a locale/language constraint imposed without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

该文件标题及全部说明内容均以中文呈现,没有说明这是特定地区/语言专用内容,也没有提供用户可选择其他语言的机制。根据语言/locale 政策,若技能内容默认强制单一语言而无用户选择,属于自然语言层面的潜在政策问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

All headings and instructions are written in Chinese, and the file provides no indication that language selection is optional or that the skill is intentionally restricted to Chinese-speaking users. Under the stated policy, fixed language behavior without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

A language or locale policy violation applies to all file types when the skill forces a specific language without user opt-in. This document uses Chinese throughout and does not indicate that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.