other
- Location
SKILL.md:26- Finding
Automatic Persistent Collection of User Information Without Explicit Consent
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 26-37 and 98-103
Vulnerability Type:other: Privacy-invasive automatic data persistence
Risk Level: MediumVulnerable Code
markdown - Proactively store durable user facts without waiting for an explicit memory command when the user shares information that is likely to matter later. - Only store facts that are explicitly stated by the user or already confirmed in the current session. - Preserve the user's phrasing when possible, and preserve the user's meaning closely when storing facts; prefer the exact claim they made over a stronger paraphrase. - Do not infer, upgrade, or invent facts. For example, "I'm learning Rust" does not mean "I am a Rust developer," and "I'm planning a demo" is not an occupation. - If a detail is ambiguous, speculative, or feels too weak to persist, do not store it. - When several explicit facts appear in one message, store only the durable facts that are likely to matter later. ## Automatic Decision Rule When the user naturally shares stable personal, project, team, or preference information, assume you should store it in ClawGraph even if they did not say "remember this." Do not store fleeting conversational filler, jokes, weak guesses, or details that are only implied.markdown - **Persistence**: Data stored at `~/.clawgraph/data` — survives restarts - **Idempotent**: Uses MERGE — adding the same fact twice won't create duplicates - **JSON output**: Always use `--output json` for structured, parseable results - **Config**: `~/.clawgraph/config.yaml` for defaults (model, db path) - **Models**: OpenAI-compatible APIs today via the OpenAI SDK. The current default model path is `gpt-5.4-mini` for ClawGraph extraction. - **Env vars**: `OPENAI_API_KEY` is required. `OPENAI_BASE_URL` is optional for other OpenAI-compatible endpoints.Technical Analysis
The Skill explicitly instructs the Agen ...[truncated 2271 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit, informed opt-in before enabling automatic memory storage.
- Ask for confirmation before storing personal, confidential, or organization-sensitive facts.
- Clearly disclose that facts may be transmitted to an external model provider for extraction.
- Deny storage of credentials, authentication tokens, financial information, health information, precise locations, and other sensitive categories by default.
- Provide documented commands to inspect, correct, and permanently delete individual facts or the complete graph.
- Define retention limits and support automatic expiration where indefinite persistence is unnecessary.
- Restrict
OPENAI_BASE_URLto administrator-approved HTTPS endpoints and clearly identify the configured data processor. - Apply restrictive filesystem permissions to
~/.clawgraph/dataand the configuration file. - Prefer local extraction or a provider with appropriate privacy and retention guarantees when processing sensitive information.
