T09 · Insecure Skill Coding Practices
- Location
SKILL.md:18- Finding
Remote embedding configuration may expose persistent memory and session transcripts to third-party providers
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This memory setup skill is purpose-aligned but needs review because it recommends indexing long-term memory and past chat transcripts with a remote embedding provider without enough privacy safeguards.
Review this before installing if your workspace or chat history contains confidential, customer, regulated, or personal data. Prefer the local provider or memory-only indexing for sensitive work, avoid storing secrets or unnecessary private details in MEMORY.md or logs, protect provider API keys in a secure environment, and confirm the embedding provider's retention and deletion terms before enabling session indexing.
SKILL.md:18Remote embedding configuration may expose persistent memory and session transcripts to third-party providers
The skill explicitly encourages enabling persistent memory search over MEMORY.md and past session transcripts, including personal preferences and project history, but provides no privacy or data-minimization warning. This can lead users to index sensitive personal or confidential workplace data into searchable storage and external embedding providers without informed consent or risk awareness.
The MEMORY.md and daily log templates encourage storing long-term facts, decisions, preferences, and ongoing logs, but do not warn against recording secrets, health data, credentials, or other sensitive information. In practice, users may treat these files as a catch-all memory store, increasing the chance of sensitive data accumulation and later retrieval or exposure through search.
The skill instructs users to set provider API keys in the environment but does not mention secure credential handling. While setting environment variables is common, the omission may still contribute to unsafe practices such as committing secrets to files, shell history, or shared workspace configuration.
No suspicious patterns detected.