T09 · Insecure Skill Coding Practices
- Location
SKILL.md:56- Finding
Unsafe Defaults Can Publicly Expose Session and File Contents
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 56–67
Vulnerability Type: Unsafe data-sharing configuration
Risk Level: HighThe documented configuration enables public visibility and file-content collection by default:
json { "skills": { "buildlog": { "apiKey": "your-api-key", "autoUpload": false, "defaultPublic": true, "includeFileContents": true, "maxFileSizeKb": 100 } } }Technical Analysis
The combination of
"defaultPublic": trueand"includeFileContents": truecreates an unsafe disclosure boundary. A buildlog may contain coding-session messages and snapshots of source files, which can include proprietary code, credentials, tokens, personal information, internal service URLs, or sensitive configuration.Although automatic upload is disabled by default, the skill documents upload and sharing commands. When a user invokes those commands, collected file contents may be uploaded with public visibility unless the configuration is changed. The documentation does not require an exact export preview, file allowlist, secret scanning, redaction, or a separate confirmation of public visibility.
SKILL.mdstates that API keys are excluded from exports, but the project contains no implementation with which to verify that guarantee. The statement also does not address other classes of secrets that may appear in conversations or files.Attack Path
- A user configures the skill using the documented defaults.
- The skill records a coding session while file-content collection is enabled.
- Sensitive information is included in session messages or captured file snapshots.
- The user invokes the documented upload or sharing functionality, or separately opts into automatic upload.
- Because public visibility is the documented default, the resulting buildlog is made publicly accessible unless the user proactively changes the settin ...[truncated 885 chars]
- Remediation
View remediation
Remediation Suggestions
- Change
defaultPublictofalseso every buildlog is private unless the user explicitly selects public visibility. - Change
includeFileContentstofalseand require explicit opt-in for each recording or export. - Display a preview listing every message, annotation, and file selected for export before upload.
- Require separate, informed confirmations for uploading data and making it public.
- Implement file allowlists and exclude sensitive paths and formats by default, including
.envfiles, private keys, credential stores, deployment configuration, and authentication files. - Scan exported messages and files for secrets, credentials, personal information, and high-entropy tokens; redact detected values or block the upload pending review.
- Keep
autoUploaddisabled and prevent it from bypassing content review or public-visibility confirmation. - Document data retention, deletion, access controls, transport security, and server-side handling.
- Add implementation-level tests demonstrating that API keys and other detected secrets cannot enter exported artifacts.
- Change
