T09 · Insecure Skill Coding Practices
- Location
photo-protocol.md:5- Finding
Minor Image Handling Policy Contradiction
- Content
View full analysis
Vulnerability Details
File Location:
photo-protocol.md:5-7
Vulnerability Type: Conflicting sensitive-image collection controls
Risk Level: MediumComplete Code Snippet:
markdown - Ask whether photo tracking is actually useful for this case. - Confirm the user is comfortable storing photo metadata locally. - Do not ask for intimate-area or minor photos unless a lawful caregiver context is already clear and the user explicitly wants tracking.This exception conflicts with categorical restrictions elsewhere in the Skill:
markdown - ask for or store intimate-area images or any photos of minorsand:
markdown - Do not request or store photos of minors. - If those contexts appear, stop image collection and direct the user to in-person or secure clinician workflows rather than local tracking.Technical Analysis
photo-protocol.md:7permits the Agent to request or track a minor's photograph when a user claims a lawful caregiver context and explicitly requests tracking. That instruction directly conflicts with the unconditional prohibitions inSKILL.md:55-59,legal-boundaries.md:12-16, andmemory-template.md:106-113.Because the Skill directs the Agent to consult
photo-protocol.mdwhen photos are involved, the more specific protocol can be interpreted as an authorized exception to the global policy. No mechanism verifies caregiver authority, the subject's age, consent, or whether the image is non-intimate. This control inconsistency can therefore result in processing sensitive medical imagery that the Skill claims it will never request or store.Attack Path
- A user states that they are the lawful caregiver of a minor.
- The user asks the Agent to establish photo tracking for the minor's skin concern.
- The Agent loads the photo protocol and applies the exception at
photo-protocol.md:7. - The Agent requests a photograph or records its file/source ...[truncated 677 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the caregiver exception and replace line 7 with an unconditional control:
markdown - Never request, receive, store, or track photographs of minors or intimate areas. Redirect the user to an approved secure clinician workflow. -
Align
photo-protocol.md,SKILL.md,legal-boundaries.md,memory-template.md, andsetup.mdso all files enforce the same rule. -
Clarify that caregiver context may support text-only triage but must never enable image collection or image-metadata storage.
-
Require the Agent to stop the photo workflow and avoid creating a photo log whenever the subject is identified as a minor.
-
Add a pre-storage validation step that checks adult status, non-intimate body location, and explicit storage approval before creating photo-related records.
-
Add tests covering conflicting requests, including caregiver claims, unclear age, and mixed adult/minor cases, to ensure the strict prohibition always prevails.
-
