Back to skill

Security audit

Apple Health Skill Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed health-data helper that fetches workouts and profile data with an API key, so it is purpose-aligned but should be used carefully with sensitive health information.

Before installing, understand that authenticated requests can expose personal workout history, heart-rate details, and profile information to the agent session and the configured health API. Use a dedicated API key if possible, query the smallest date range needed, avoid sharing raw results unnecessarily, and revoke the key if you no longer use the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill retrieves authenticated personal health and workout data without presenting a clear user-facing privacy warning or explicit consent reminder near those operations. In an agent context, this increases the chance that sensitive biometric and activity data is fetched or displayed without the user fully understanding the privacy implications, especially because the skill advertises easy access and includes executable tooling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.