T09 · Insecure Skill Coding Practices
- Location
SKILL.md:93- Finding
Plaintext Storage of Sensitive Event, Ticket, and Attendance Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:11,SKILL.md:38-39, andSKILL.md:93-98
Vulnerability Type: Plaintext sensitive-data storage without access-control or retention safeguards
Risk Level: MediumVulnerable Code Snippets
SKILL.md:11:markdown - Create `~/events/` as workspaceSKILL.md:38-39:markdown Section 112, Row 8 Confirmation: TM-789456SKILL.md:93-98:markdown ## What To Track - Date, time, location - Tickets/confirmation numbers - Logistics (parking, doors, dress code) - Who you're going with - RSVPs when hostingTechnical Analysis
The Skill directs the Agent to create a persistent workspace under the user's home directory and store ticket confirmation numbers, event locations, attendance relationships, and RSVP information in Markdown files. These records may contain security-sensitive ticket identifiers and personal information about the user and third parties.
The instructions do not require owner-only file permissions, encryption, identifier redaction, user consent before retaining third-party information, or a retention and deletion policy. Consequently, the default implementation can leave sensitive records exposed to other locally authorized users or processes, backup software, indexing services, and synchronization tools that can access the workspace.
The example confirmation number is illustrative rather than a real embedded credential. The risk arises from instructing the Agent to place future user-supplied confirmation numbers and personal event data into plaintext storage.
Attack Path
- The user activates the Skill and asks the Agent to track an event.
- The Agent creates the documented
~/events/workspace. - The user supplies a ticket confirmation number, appointment information, event location, companion details, or guest RSVP data.
- Following the Skill instructions, the Agent writes that info ...[truncated 1271 chars]
- Remediation
View remediation
Remediation Suggestions
- Store only non-sensitive event summaries by default and require explicit user consent before retaining confirmation numbers, appointment details, or third-party RSVP information.
- Redact confirmation identifiers in routine views, retaining only a short suffix when the complete value is unnecessary.
- Create the workspace and files with owner-only permissions, such as directory mode
0700and file mode0600on platforms that support POSIX permissions. - Provide an encrypted or operating-system-protected storage option for ticket and reservation credentials instead of ordinary Markdown.
- Warn users that the workspace may be included in backups, search indexes, or cloud synchronization, and allow them to choose a protected location.
- Define retention controls that archive or delete sensitive ticket and RSVP data after the event.
- Minimize third-party personal data, record it only for the stated event-management purpose, and support review and deletion on request.
- Ensure logs, generated calendar summaries, and surfaced reminders do not reproduce complete confirmation numbers.
