T09 · Insecure Skill Coding Practices
- Location
references/bill-templates.md:202- Finding
Plaintext Collection of Full Financial Account Identifiers
- Content
View full analysis
Vulnerability Details
File Location:
references/bill-templates.md, lines 202 and 209
Vulnerability Type: Plaintext sensitive financial data collection
Risk Level: MediumVulnerable Code Snippet
text Account Info: [Account Number]text [ ] Auto-debit Debit Account: [Account]Technical Analysis
The recurring-bill template asks users to enter an account number and debit account without requiring masking or limiting the value to a non-sensitive alias. Full financial account identifiers are unnecessary for bill organization; a user-defined account name or the last four digits would provide sufficient differentiation.
Because the Skill operates through conversational and document-based records, users following this template may place account identifiers in plaintext chat histories, logs, exports, backups, or copied tracking documents. The Skill provides no warning against entering complete account numbers and no guidance concerning redaction, secure storage, access control, or retention.
This is a data-minimization and sensitive-data-handling weakness. The audit found no mechanism that automatically transmits or exploits the information.
Attack Path
- A user invokes the recurring-bill management workflow.
- The Agent presents the template containing
Account Info: [Account Number]orDebit Account: [Account]. - The user follows the template and supplies a complete financial account identifier.
- The identifier is retained in plaintext within conversation history, platform logs, exports, backups, or a copied bill-management document.
- An attacker or unauthorized person who later obtains access to those records recovers the identifier.
- The exposed information may be used for targeted phishing, social engineering, identity correlation, or financial-account reconnaissance.
Impact Assessment
Successful exploitation does not directly grant banking privileges, authorize payments, or expose credentials ...[truncated 353 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace full-account fields with masked, non-sensitive identifiers:
text Account Alias: [e.g., Household Checking] Account Identifier: [Last 4 digits only]- Add an explicit warning adjacent to every financial identifier field:
text Never enter a full bank or card number, PIN, password, security code, authentication token, or online-banking credential.-
Apply the same minimization standard to related fields, including
Receiving Account,Transaction ID, and any imported transaction records. Use aliases, truncated references, or redacted values wherever possible. -
Add privacy guidance covering:
- Redaction before importing statements or receipts
- Least-privilege access to exported records
- Encryption for locally stored financial documents
- Minimal retention and secure deletion
- Avoidance of sensitive financial data in shared calendars or notes
-
Revise the Privacy Note in
SKILL.mdso that it clearly distinguishes the Skill's lack of intentional third-party transmission from the possibility that conversation platforms may retain user-provided content.
