fitbit
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalySUSPICIOUS. The skill's purpose and capabilities are aligned: it only describes read-only Fitbit health queries and device/account lookups. Data flow is proportionate and appears to use Fitbit's official OAuth/API endpoints rather than a proxy, which lowers exfiltration concern. The main risk is install/execution trust: the required `fitbit-cli` is an unofficial third-party tool from a personal publisher, not Fitbit, and the skill asks the agent/user to rely on that tool for access to sensitive health data and OAuth tokens. Because distribution is via PyPI/GitHub with visible source and release history, this is not confirmed malware, but it remains a meaningful supply-chain and credential-forwarding risk relative to the skill's stated purpose.