other
- Location
SKILL.md:211- Finding
Unnecessary Transmission of Persistent User Activity to a Third-Party Service
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 211–222; related workflows at lines 289–308
Vulnerability Type: Privacy-sensitive data transmission
Risk Level: MediumVulnerable code:
markdown ### 5. Record Progress **`POST /pyq-api/progress`** — Record a user's answer to a question. ```bash curl -X POST "https://qqqditxzghqzodvauxth.supabase.co/functions/v1/pyq-api/progress" \ -H "Authorization: Bearer $PREPSPSC_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "external_user_id": "user123", "question_id": "uuid-here", "selected_option": "c", "is_correct": true, "time_spent_seconds": 45 }'text The documented workflows further direct the agent to record individual or complete answer histories: ```markdown 4. `POST /pyq-api/progress` — Record each answer 5. `GET /pyq-api/analytics?user_id=xxx` — Show performance summarymarkdown 5. Record all answers via `POST /pyq-api/progress` 6. Show analytics via `GET /pyq-api/analytics`Technical Analysis
The Skill instructs an agent to send a persistent external user identifier, question identifier, selected answer, correctness result, and time spent to a third-party Supabase endpoint. Bookmark functionality also permits user-authored notes to be sent to the same service.
This network behavior is declared rather than concealed. However, it exceeds the minimum privileges needed for the Skill's core question-search and mock-test functionality. The documentation does not require the agent to obtain informed user consent, disclose the transmitted fields, use anonymous identifiers, avoid personally identifying values, or offer local-only progress tracking.
A stable or reused
external_user_idallows answer activity to be linked across sessions. If it contains an email address, account name, or another identifying value, educational performance data could become directly at ...[truncated 1157 chars]- Remediation
View remediation
Remediation Suggestions
- Make progress tracking, analytics, and bookmarks explicitly opt-in rather than part of the default practice workflow.
- Before transmission, disclose the destination, purpose, exact fields, expected retention, and applicable deletion mechanism.
- Keep answer history and timing data local or session-only unless the user affirmatively enables synchronization.
- Generate a random, opaque, service-specific identifier instead of accepting email addresses, usernames, account IDs, or other identifying values.
- Minimize collected fields. Do not transmit timing, correctness, or notes unless they are required for a feature the user requested.
- Document retention limits and provide mechanisms to export and delete stored progress.
- Avoid recording free-form bookmark notes by default because they may contain personal or sensitive information.
- Add explicit Skill instructions prohibiting silent transmission and requiring user confirmation before persistent tracking begins.
