fitbit

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are aligned: it only describes read-only Fitbit health queries and device/account lookups. Data flow is proportionate and appears to use Fitbit's official OAuth/API endpoints rather than a proxy, which lowers exfiltration concern. The main risk is install/execution trust: the required `fitbit-cli` is an unofficial third-party tool from a personal publisher, not Fitbit, and the skill asks the agent/user to rely on that tool for access to sensitive health data and OAuth tokens. Because distribution is via PyPI/GitHub with visible source and release history, this is not confirmed malware, but it remains a meaningful supply-chain and credential-forwarding risk relative to the skill's stated purpose.

Confidence: 90%Severity: 64%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:19 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Ffitbit%2F@81b64ae20c5563c66ebc9564e455dd20c1a15c7719292ad2b6607f42eb8eb0f4
Security Audit — socket — fitbit