other
- Location
SKILL.md:9- Finding
Excessive Persistent Conversation Profiling Without Privacy Controls
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:9,SKILL.md:151-154,SKILL.md:249-258; supporting evidence incultivator_data.json:1-4,72-81
Vulnerability Type:other: Excessive persistent conversation data retention
Risk Level: MediumVulnerable Instructions
The following is an English rendering of the complete relevant instruction segments from
SKILL.md:text This skill parses every user question and every received answer. After analyzing the question and answer, it extracts key nouns and core concepts and summarizes them in a structured form, including but not limited to objects, skills, realms, relationships, factions, affinity, and any other content found in novels. It analyzes the type of information, places it into the fictional world, estimates how it changes the protagonist, and finally writes the resulting content to a file for continued accumulation.text At the end of every conversation: 1. Write the modified data to {baseDir}/cultivator_data.json. 2. Ensure that all required fields exist, including currency, vehicles, and current_quests.text After every user question and answer, the following growth processing must occur: 1. experience: calculate base growth, event growth, and task growth. 2. happiness: increase according to question value and completion. 3. knowledge_gained: record the core knowledge from the answer. 4. Skill acquisition: automatically record new skill concepts in skills. 5. Task progress: update current_quests when applicable. 6. Reputation: update reputation based on behavior. 7. Title: update the title when conditions are met. 8. Daily activity tracking: update streaks and perfect-day statistics.The persisted profile is demonstrated by
cultivator_data.json:json { "user_name": "Rain", "world_selected": true, "level": 0, "experience": 10, "happiness": 0, "health": 100, "energy": 100, "morality": 60, "reputation": 0, "items": [], "skills": [ ...[truncated 3493 chars]- Remediation
View remediation
Remediation Suggestions
-
Require explicit opt-in consent
- Disable persistent tracking by default.
- Explain which fields will be stored, why they are needed, and how long they will be retained.
- Keep ordinary assistant use available when tracking is declined.
-
Apply data minimization
- Store only gameplay state that the user explicitly chooses to retain.
- Do not retain raw questions, raw answers, inferred relationships, health information, morality, or behavioral classifications by default.
- Separate fictional character attributes from factual user attributes.
-
Add sensitive-data filtering
- Detect and redact passwords, API keys, authentication tokens, financial details, medical information, precise locations, and other sensitive personal data before persistence.
- Refuse to place secrets in
notes,last_question,last_analysis, event logs, or knowledge fields.
-
Introduce retention limits
- Remove
last_questionandlast_analysisafter the active session unless the user explicitly saves them. - Expire event logs and task history after a documented period.
- Set finite maximum sizes for all historical collections.
- Remove
-
Provide user controls
- Add commands such as
/privacy,/stored-data,/export-data,/forget-last, and/delete-all-data. - Allow users to disable individual profile categories.
- Require confirmation before destructive deletion.
- Add commands such as
-
Harden local storage
- Create the data file with permissions restricted to the owning user, such as mode
0600. - Avoid shared or globally readable directories.
- Use encryption at rest when the runtime provides secure key management.
- Ensure backups and synchronization systems apply equivalent access controls.
- Create the data file with permissions restricted to the owning user, such as mode
-
Validate all persisted content
- Enforce a strict schema and bounded field lengths.
- Treat stored user content as untrusted data.
- Never reinterpret stored notes or questions as agent i ...[truncated 282 chars]
-
