T09 · Insecure Skill Coding Practices
- Location
setup.md:20- Finding
Plaintext Persistence of Sensitive Health Data Without Privacy Controls
- Content
View full analysis
Vulnerability Details
File Location:
setup.md:20-25, with the stored fields defined inmemory-template.md:15-19
Vulnerability Type: Plaintext storage of sensitive personal and health information
Risk Level: MediumVulnerable Code
markdown Write to config or memory **only** when the user states something in the course of the work — never as a preflight. - User names units, energy unit, summary cadence, or how they want ambiguity handled → update the matching key in `~/Clawic/data/calories/config.yaml`. - User reveals a goal, stats, restrictions, staple foods, an external tracker, or a weigh-in habit → record under the relevant preference area in `~/Clawic/data/calories/memory.md`. - User corrects an estimate ("that pasta was actually 700") → update the library entry; corrected entries outrank estimates forever. - User discloses anything from the Red Flags table → record it in memory's Health Context section so the guardrail persists across sessions.The corresponding memory template contains:
markdown ## Stats <!-- weight (7-day avg), height, age, sex as given — only what was volunteered or needed for a target --> ## Health Context <!-- Red Flags disclosures: meds, conditions, pregnancy, ED history — persists the guardrail (safety.md) -->Technical Analysis
The skill directs the Agent to persist body measurements and highly sensitive health information—including medication use, medical conditions, pregnancy status, and eating-disorder history—in Markdown files under
~/Clawic/data/calories/.Although persistence is limited to information disclosed during ordinary use, the project does not require explicit informed consent before storing health data. It also does not specify owner-only filesystem permissions, encryption, data minimization, retention periods, automatic expiration, redaction, or a process through which users can inspect and delete their records.
Consequently, the confidentiality of these records d ...[truncated 1699 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit, informed opt-in before persisting health information, separately from ordinary food-library storage.
- Default sensitive health context to session-only storage unless the user requests persistence.
- Minimize stored information. Persist a coarse safety state such as
clinician_target_required: trueinstead of detailed diagnoses or medication names whenever possible. - Create the data directory and files with owner-only permissions, such as directory mode
0700and file mode0600, where the platform supports permission management. - Use encrypted storage or an operating-system credential/privacy store for medical context.
- Define a retention policy with automatic expiration for stale health and tracking records.
- Provide documented commands or workflows to view, correct, export, selectively redact, and permanently delete stored data.
- Warn users when their home directory is synchronized or backed up to third-party services.
- Separate low-sensitivity preferences and food-library data from health context so access and retention policies can be applied independently.
- Add tests or output gates that prevent sensitive data from being written before consent and verify secure permissions after file creation.
