Back to skill

Security audit

Fitness Daily - 健身自律打卡

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local fitness checklist that stores a user-selected daily CSV log and does not show hidden, networked, destructive, or credential-seeking behavior.

Before installing, expect this skill to create or update a local fitness log at ~/.fitness-daily.csv by default, or at another path if you pass --log. Review the health disclaimer and treat the checklist as personal habit tracking, not professional medical, nutrition, or training advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises commands that read and write a local log file, but the manifest declares no explicit tool scope or permissions boundary. That mismatch can cause the platform or user to underestimate the skill’s file-system capabilities, increasing the chance of unintended local file access or overwriting if the implementation is changed or misused.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrases are broad, generic fitness and habit-tracking terms without clear scope guards, so the skill may activate in contexts where the user did not intend to use it. Unintended invocation is less severe here because the skill is a simple checklist, but it could still lead to confusing behavior or accidental file operations such as writing a log entry.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains user-facing descriptions, prompts, help text, and output entirely in Chinese, which effectively forces a specific language for interaction. The policy allows locale constraints only when the skill offers opt-in choice or clearly documents a justified region-specific limitation, neither of which appears here.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/fitness.py (reported line 382)May include surrounding context.

python
help='打卡记录文件路径(默认 ~/.fitness-daily.csv)')

    args = parser.parse_args()
    args.date = args.date or __import__('datetime').date.today().isoformat()

    commands = {
        'check': cmd_check,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation is presented only in Chinese, including usage instructions and disclaimers, which can effectively force a specific language on users without explicit opt-in. The policy for natural-language violations applies to markdown files, and no alternative locale or user language choice is mentioned here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The display name and description are presented in Chinese, but the manifest does not state that the skill is China/Chinese-specific or that users can opt into this language. That can create a language/locale policy issue if the broader environment expects skills not to force a language without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.