T09 · Insecure Skill Coding Practices
Warning
- Location
- new_context.md:10
- Finding
- Plaintext Disclosure of Sensitive Personal Calendar Data## Vulnerability Details **File Location**: `new_context.md`, lines 10-26 **Vulnerability Type**: Plaintext sensitive-data exposure **Risk Level**: Medium ### Vulnerable Content ```markdown ### Yesterday (2026-09-02) - Island Coatings Quote, 12:30 - Breakfast at leahi health, 13:15 - Reservation at Hau Tree, 13:30 - HNL flight to SFO, 16:20 ### Today (2026-09-03) - Cleaners Arrive, 09:30 - Jon Collins meeting, 11:00, Microsoft Teams - EDD RESEA Virtual Appointment, 15:00 - Reservation at Firefly Restaurant, 17:30 ### Tomorrow (2026-09-04) - DEXA scan at BodySpec San Francisco, 09:57 - Zoom with Jared and Brandon Edwards, 12:00 - Derm Botox, 16:15 - Dinner with Evan, Alex, Michael, Kathy, 18:00 ``` ### Technical Analysis The project includes what appears to be a generated daily-context artifact containing specific travel, employment, medical, meeting, and social schedule details. Because this file is part of the distributable project, every person or system receiving the project can read the information without authentication or calendar-account access. This crosses the trust boundary between the calendar owner's private data and project recipients. The exposure occurs merely through project distribution; executing the Skill is unnecessary. ### Attack Path 1. The project publisher includes `new_context.md` in the Skill package or repository. 2. An unauthorized recipient downloads, clones, or otherwise obtains the project. 3. The recipient opens the plaintext Markdown file. 4. The recipient extracts dates, times, locations, travel plans, medical appointments, and participant names. 5. The information may then be used for profiling, targeted phishing, social engineering, or physical-security planning. ### Impact Assessment The exposed scope includes: - Flight timing and destination information. - Medical and cosmetic appointment details. - Employment-related appointment information. - Meeting platforms and participant identities. - Restaurant reservati ...[truncated 303 chars]
- Remediation
- ## Remediation Suggestions 1. Remove `new_context.md` from the distributed project. 2. Purge the file from repository history and assess whether published package versions or mirrors require takedown. 3. Replace operational examples with clearly synthetic names, dates, locations, and events. 4. Add generated context artifacts such as `new_context.md` to `.gitignore` and packaging exclusion rules. 5. Store generated daily context only in the intended private profile location rather than the Skill source tree. 6. Add pre-commit and release checks that detect calendar exports, medical terms, personal email addresses, participant names, and other private snapshot data. 7. Review access logs and distribution history to determine who may already have received the exposed information.
