T09 · Insecure Skill Coding Practices
- Location
SKILL.md:20- Finding
Plaintext Persistence of Potentially Sensitive Configuration and Account Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This memory-management skill is understandable in purpose, but it asks the agent to persist account/API information and copy an OpenClaw config file into a Desktop archive without safeguards.
Review before installing. This skill should only be used if you are comfortable with the agent writing long-lived local memory files. Do not let it archive raw config files, tokens, credentials, account details, or API keys; use redacted task summaries only and require explicit confirmation before any write or recall from the archive.
SKILL.md:20Plaintext Persistence of Potentially Sensitive Configuration and Account Data
The skill directs the agent to persist account information, API-related changes, task progress, and project state into local memory files for future retrieval. In a memory-management skill, this is especially risky because it normalizes long-term retention of potentially sensitive data and makes later disclosure more likely, whether through accidental recall, local compromise, or overbroad reuse.
The skill instructs archiving account information and configuration-related material without any warning, minimization, or secret-handling safeguards. That is dangerous because persistent storage of sensitive operational data increases the attack surface and can expose credentials or private account details through later access, sync, or local compromise.
The example command copies a local configuration file directly into the work folder, encouraging durable storage of a file that may contain tokens, credentials, or other sensitive settings. Providing this as a ready-to-use command materially increases the likelihood of unsafe secret persistence and later exposure.
The activation conditions are broad enough that the skill could be invoked in many ordinary conversations without clear user consent or scope boundaries. Because this skill writes to persistent local storage and handles prior-session memory, ambiguous triggering increases the chance of unintended data retention or access.
All user-facing instructions, triggers, and workflow text are in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can constitute a language/locale policy issue when a skill imposes one language by default without opt-in.
The workflow tells the agent to consult stored files when answering questions about prior conversations, creating a mechanism to retrieve previously archived sensitive data outside the original context. When combined with the archival instructions, this increases the chance of privacy leakage and unauthorized resurfacing of old user information.
The trigger table uses broad conditions like completing important tasks or being asked about prior matters, without limiting scope or requiring user approval. In this skill context, those triggers can cause automatic persistence or retrieval of user data from local files, which raises privacy and over-collection risks.
The skill explicitly instructs copying a local configuration file into a persistent archive directory, which expands the skill from benign memory management into handling potentially secret-bearing configuration material. Config files commonly contain tokens, endpoints, or user-specific secrets, so persisting them for later retrieval creates an unnecessary disclosure and retention risk.
The phrase 'every so often check context usage' is vague because it provides no concrete interval, event hook, or stopping condition. This ambiguity can lead to inconsistent or overly frequent invocation of the skill's checking behavior.
No suspicious patterns detected.