T09 · Insecure Skill Coding Practices
- Location
setup.md:11- Finding
Persistent Plaintext Storage of Sensitive Fitness and Health Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The fitness skill is coherent, but it stores sensitive workout and health details in plaintext local files without an explicit opt-in, retention policy, or access-control guidance.
Before installing, be aware that this skill can create and reuse plaintext fitness records in your home directory, including injuries, heart-rate data, bodyweight, sleep, schedule constraints, and missed-session reasons. Use it only if you are comfortable with that local persistence, and consider restricting file permissions, avoiding cloud sync for the folder, and periodically reviewing or deleting stored records.
setup.md:11Persistent Plaintext Storage of Sensitive Fitness and Health Data
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
last: YYYY-MM-DD
## Baselines
<!-- Derived from log.md; recompute when they shift, keep the date -->
| Metric | Value | As of |
|---|---|---|
| e1RM squat | 120 kg | YYYY-MM-DD |
The manifest says the Fitness skill is for training-plan design and is 'Not for meal-level nutrition planning.' Line L03 states that calorie targets, macro math, and meal planning are part of this content flow, even if routed to another skill, which expands beyond the training-focused scope described in the manifest.
The template explicitly stores health- and fitness-related data such as injury history, resting heart rate, attendance, and training baselines in local files, but provides no warning about the sensitivity of that data or guidance on minimization, retention, or access control. Even though the storage is local, these files could be exposed through backups, sync tools, shared machines, or later agent actions, resulting in privacy leakage of sensitive personal information.
The skill explicitly instructs the agent to read from and write to multiple user-local files containing sensitive health and profile data, but provides no user-facing notice, consent step, or transparency about persistence. Because this is a fitness skill, the data includes potentially sensitive health-related information such as injury history, resting heart rate, bodyweight, age, and exclusions, making silent collection and storage riskier than ordinary preference caching.
The instructions direct persistent storage of user fitness, health, schedule, and wearable data across config, memory, and log files whenever such details are mentioned in normal conversation, without a strong necessity boundary or explicit opt-in. This creates unnecessary accumulation of sensitive longitudinal data, increasing privacy exposure and the chance of misuse, over-retention, or unintended reuse in later sessions.
No suspicious patterns detected.