fitbit
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on the execution of the 'fitbit-cli' tool to interact with the Fitbit API and retrieve health metrics.
- Evidence: Shell commands in 'SKILL.md' such as 'fitbit-cli -s', 'fitbit-cli -e', and 'fitbit-cli -u'.
- [EXTERNAL_DOWNLOADS]: The skill requires an external binary dependency to be present on the system.
- Evidence: The 'metadata' section in 'SKILL.md' lists 'fitbit-cli' under 'requires.bins'.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the Fitbit API, which represents a potential attack surface for indirect prompt injection.
- Ingestion points: The output of health data queries from 'fitbit-cli' is ingested into the agent context.
- Boundary markers: No explicit delimiters or warnings to ignore instructions within the retrieved data are present in the skill instructions.
- Capability inventory: The agent can execute the 'fitbit-cli' binary and access user health metrics.
- Sanitization: No sanitization or validation logic for the external health data is described in the provided files.
Audit Metadata