T09 · Insecure Skill Coding Practices
- Location
setup.md:58- Finding
Plaintext Persistent Storage of Highly Sensitive User Data Is Explicitly Permitted
- Content
View full analysis
Vulnerability Details
File Location:
setup.md:58-65
Vulnerability Type: Sensitive data stored in an unprotected persistent Markdown file
Risk Level: HighRelevant Code:
markdown Keep `~/california/memory.md` lightweight and useful: - activation preference for California topics - current mode and target region - major deadlines, open loops, and dependencies - persistent family, school, housing, transit, and hazard constraints - which official portals or local agencies already matter for this user Do not store credentials, account numbers, SSNs, full street addresses, immigration-status details, or payment details unless the user explicitly asks for that behavior.The behavior also conflicts with the security claim in
SKILL.md:116-121:markdown **Data that stays local:** - Region preference, move timeline, family constraints, vehicle notes, and open tasks in `~/california/` **This skill does NOT:** - Submit government forms on the user's behalf without explicit instruction - Store credentials, SSNs, or payment information in local memoryTechnical Analysis
The setup instructions permit credentials, account numbers, Social Security numbers, full street addresses, immigration-status details, and payment details to be written to
~/california/memory.mdwhenever the user explicitly requests it. The memory file is an ordinary Markdown document, and the Skill specifies no encryption, restrictive filesystem permissions, secret-store integration, retention period, access review, or secure deletion procedure.User consent does not make plaintext secret storage secure. Sensitive values persisted in this form may be exposed to other local users or processes, malware, backup software, cloud synchronization, diagnostic collection, or later Agent sessions. The conflicting statement in
SKILL.mdmay additionally give users the inaccurate impression that these data classes can neve ...[truncated 1312 chars]- Remediation
View remediation
Remediation Suggestions
- Replace the exception with an absolute prohibition against storing credentials, authentication tokens, SSNs, account numbers, payment data, immigration-status details, and other high-impact identifiers.
- Do not treat user consent as sufficient authorization to place secrets in a plaintext memory file.
- Store only coarse, non-sensitive preferences necessary for California-related continuity.
- If a legitimate feature ever requires secret retention, use an operating-system credential manager or dedicated encrypted secret store rather than Markdown.
- Create allowed memory files with owner-only permissions, such as mode
0600on supported systems, and verify ownership before reading or updating them. - Define retention and deletion procedures, including a user-facing command to inspect and permanently remove stored memory.
- Make
setup.md,memory-template.md, andSKILL.mdconsistent about prohibited data classes. - Before every write, show the categories to be stored and obtain confirmation without reproducing sensitive values in logs or confirmation messages.
