Back to skill

Security audit

sleep-debt-calculator

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local sleep-tracking CLI, but users should know it stores sleep and lifestyle notes in a plaintext file in their home directory.

Install only if you are comfortable with sleep history, age, quality ratings, and any notes being stored locally in plaintext at ~/.sleep_debt.json. Avoid putting highly sensitive details in notes, check local file permissions on shared machines, and delete the file when you want to reset or remove the data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sleep_debt.py:75
Finding

Potentially Sensitive Health Data Stored Without Enforced Restrictive File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documentation describes local file read/write behavior via a JSON database but does not declare any tool scope such as permissions or allowed-tools. Missing capability disclosure weakens sandboxing and review controls because consumers cannot clearly assess that the skill persists user data to disk, which is especially relevant for health-related information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill collects and stores sensitive health and lifestyle information, including sleep patterns and notes about caffeine or alcohol use, in a local JSON file without a clear privacy warning. Users may unknowingly persist sensitive personal data in plaintext on shared or insecure systems, increasing the risk of unintended disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README explicitly states that sleep data is stored in ~/.sleep_debt.json and encourages free-text notes that may include sensitive behavioral and health-adjacent information such as sleep quality, caffeine use, and alcohol use, but it gives no privacy warning or guidance on local file protections. This is not a code-execution issue, but it is a legitimate privacy weakness because users may unknowingly store sensitive personal data in a predictable plaintext location accessible to other local users, backups, or synced home directories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This document gives health-related recommendations with specific durations and recovery strategies before clearly stating that it is not individualized medical advice. In a sleep-health skill, users may treat the guidance as personalized or clinically authoritative, which can delay appropriate care or encourage overreliance on generalized advice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This reference includes health and impairment claims such as equivalence to sleep deprivation and being legally drunk, but it does not clearly warn users that the material is general educational information rather than personalized medical or safety advice. In a sleep-tracking skill, users may over-rely on these statements for self-assessment or delay appropriate professional help, especially when fatigue can affect driving, work safety, or health decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code normalizes average bedtime with avg_bed % 24.0 at L543, so avg_bed_normalized is always in the range [0,24). The subsequent branch at L558-L563 checks for values < 24.5 and then an else case labeled 'Extreme Night Owl', making the 'Extreme Night Owl' path unreachable even though the comments/output claim that chronotype can be classified that way.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.