T09 · Insecure Skill Coding Practices
- Location
SKILL.md:21- Finding
Plaintext Persistence of Sensitive Health and Fitness Data Without Access-Control Requirements
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:21-49;progress.md:93-105
Vulnerability Type: Plaintext sensitive-data storage with unspecified filesystem permissions
Risk Level: MediumRelevant snippet from
SKILL.md:markdown User preferences persist in `~/gym/memory.md`. Create on first use: ```markdown ## Level <!-- beginner | intermediate | advanced --> ## Goals <!-- strength | hypertrophy | fat-loss | general-fitness | powerlifting --> ## Schedule <!-- Days available. Format: "days | frequency" --> <!-- Examples: Mon/Wed/Fri, 3x/week, daily --> ## Session Duration <!-- 45min | 60min | 90min --> ## Restrictions <!-- Injuries, equipment limits, mobility issues --> <!-- Examples: Lower back injury (no deadlifts), Home gym (no cable machine) -->Fill on first conversation. Update as goals evolve.
Data Storage
Store workout logs and measurements in ~/gym/:
- workouts — Session logs (date, exercises, sets, reps, weight)
- prs — Personal records by exercise
- measurements — Body measurements, weight trends
text **Relevant snippet from `progress.md`:** ```markdown Store in `~/gym/measurements.md`:2024-01-01
- Weight: 82.5kg (morning, fasted)
- Chest: 102cm
- Waist: 84cm
- Hips: 98cm
- Arms: 38cm
- Thighs: 60cm
Notes
- Measure same time, same conditions
text ### Technical Analysis The Skill explicitly directs the agent to persist injury restrictions, body measurements, weight trends, workout history, and personal records in Markdown files under `~/gym`. These records may constitute sensitive health and fitness information. The storage instructions do not require the agent to: - Create `~/gym` with owner-only permissions. - Create data files with a restrictive mode such as `0600`. - Check whether existing files are symbolic links or owned by another user. - Obtain consent ...[truncated 2002 chars]- Remediation
View remediation
Remediation Suggestions
- Require explicit user consent before persisting injury details, body measurements, or other sensitive information.
- Create
~/gymwith owner-only permissions, such as mode0700, and verify its ownership before use. - Create all data files with mode
0600; do not rely solely on the process umask. - Use safe file-creation semantics that reject symbolic links and avoid overwriting files owned by another principal.
- Store only the minimum information required for the requested functionality. Avoid retaining detailed medical information when a less-sensitive restriction is sufficient.
- Clearly disclose which fields are retained, where they are stored, and how long they remain available.
- Provide commands or documented procedures to inspect, export, redact, and permanently delete retained records.
- Consider encryption at rest using an operating-system credential store or user-controlled encryption key when sensitive records must persist.
- Apply retention limits and remove stale measurements, injury notes, and workout history unless the user opts into longer retention.
- Avoid writing sensitive values to diagnostic logs, temporary files, or broadly accessible backup and synchronization locations.
