T09 · Insecure Skill Coding Practices
- Location
scripts/habit-cli.js:10- Finding
Habit and Health Data Stored in Plaintext Without Explicit Restrictive Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent local habit-tracking CLI, with disclosed local data storage and optional reminder automation, but users should treat habit notes as potentially private data.
Install only if you are comfortable with a local Node.js tool storing habit names, schedules, completion history, and notes in plaintext under ~/.config/habit-tracker. Avoid putting sensitive medical or personal details in notes, review any cron entries before adding them yourself, and be careful with the delete command because it removes associated log history.
scripts/habit-cli.js:10Habit and Health Data Stored in Plaintext Without Explicit Restrictive Permissions
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Referenced artifact was not completely inspected
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Usage Scenarios
### Scenario 1: Create and Start Tracking a New Habit
**User input:** "I want to track my daily reading habit — read for 30 minutes every evening"
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`), explains what it records, and suggests a realistic starting target.
The instruction 'When a user asks for habit advice' is broad enough to activate the skill for generic advice requests rather than only explicit habit-tracking intents. Over-broad routing can cause the agent to surface commands, reminders, or local automation guidance in contexts where the user did not clearly request this tool, increasing the chance of inappropriate action suggestions or unintended data handling.
The 'Event-based triggers (e.g., after completing a task)' integration guidance is ambiguous and does not define what system emits events, what permissions are required, or what actions are allowed. In an agent environment, vague event triggers can lead to unexpected autonomous invocation and command suggestions tied to unrelated workflows, expanding the skill's operational scope beyond user-initiated habit tracking.
The delete command removes both the selected habit and all associated log history, which is an irreversible data-loss operation. Although the help text states that deletion will remove logs, the runtime code provides no confirmation step or additional user-facing warning before performing the deletion.
No suspicious patterns detected.