T09 · Insecure Skill Coding Practices
- Location
SKILL.md:12- Finding
Non-Consensual Persistence of Potentially Sensitive Conversation Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-19, 31-40, and 92-96
Vulnerability Type: Automatic plaintext retention without consent or data filtering
Risk Level: MediumVulnerable Code
markdown ## Core Function: Automatic Memory **Without user confirmation, automatically record all conversation content** in daily memory files. ### Recording Rules - At the end of each session, automatically write to `memory/YYYY-MM-DD.md` - Recorded content: tasks, projects, decisions, and pending items - Keep the summary concise but completebash # Obtain the current date date +%Y-%m-%d # Append to memory/YYYY-MM-DD.md echo "- $(date '+%H:%M') | Conversation summary" >> memory/$(date +%Y-%m-%d).mdmarkdown - Automatically write to memory at the end of every conversation - Keep summaries concise and under 200 characters - If no memory exists, tell the user that this is a new session with no historical context - Respect user privacy and do not filter content; users can delete it themselves - Memory older than 30 days may periodically be archived or deletedTechnical Analysis
The skill instructs the agent to persist summaries from every conversation without obtaining user confirmation. The supplied shell command appends those summaries to date-based workspace files in plaintext.
No controls are defined for detecting or excluding credentials, authentication tokens, personal information, confidential source code, or other sensitive content. The explicit instruction not to filter content undermines data minimization and makes it more likely that sensitive values will be retained. The proposed 30-day cleanup is optional rather than mandatory and does not address access control, secure deletion, encryption, or user isolation.
This is an insecure storage practice rather than evidence of deliberate exfiltration. The audited project contains no network transmission ...[truncated 1427 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace automatic recording with explicit, informed opt-in and provide a clear indication whenever memory is written.
- Default to storing no conversation content unless persistence is necessary for a user-selected task.
- Apply mandatory redaction for passwords, API keys, access tokens, private keys, financial data, personal identifiers, and other sensitive values.
- Store only minimal task state, such as a task identifier, current milestone, and non-sensitive pending actions.
- Segregate memory by user, workspace, and project, with restrictive filesystem permissions.
- Define and enforce a fixed retention period instead of stating that old records merely “may” be deleted.
- Provide commands to inspect, edit, disable, and securely delete retained memory.
- Avoid shell-based string interpolation for generated content. Use a constrained file-writing API with explicit path validation and safe encoding.
- Consider encryption at rest when stored memory may contain confidential project information.
