T09 · Insecure Skill Coding Practices
- Location
setup.md:64- Finding
Plaintext Persistence of Sensitive Personal and Financial Data
- Content
View full analysis
Vulnerability Details
File Location:
setup.md:64-71
Vulnerability Type: Sensitive data stored in plaintext persistent memory
Risk Level: MediumVulnerable Code Snippet
markdown Keep `~/orlando/memory.md` lightweight and useful: - activation preference for Orlando topics - current mode, timeline, and preferred base area - park priorities, lodging pattern, or move shortlist - major family, school, healthcare, or commute constraints - open loops such as district comparison, park strategy, or Florida filing tasks Do not store passports, ticket numbers, payment details, insurance IDs, or exact home addresses unless the user explicitly asks for that behavior.Technical Analysis
The final instruction creates an exception that permits passport information, ticket numbers, payment details, insurance identifiers, and exact home addresses to be stored when a user requests it. The designated storage mechanism is
~/orlando/memory.md, a persistent plaintext Markdown file.The Skill specifies no encryption, restrictive file permissions, data minimization controls, automatic redaction, retention period, secure deletion process, or validation preventing secrets from entering memory. User consent does not mitigate the technical risks of storing authentication-adjacent, financial, healthcare, identity, and precise-location information in plaintext.
This instruction also conflicts with the stronger privacy statement in
SKILL.md:199-201, which states that the Skill does not store passport numbers, payment data, or health-insurance identifiers. The contradictory policy could cause the Agent to apply the weaker rule and persist information users reasonably expect never to be stored.Attack Path
- The Skill is activated for an Orlando-related conversation.
- Persistent memory is enabled under
~/orlando/memory.md. - A user, malicious prompt, or untrusted copied content asks the Agent to remember a passport number, payment detail, in ...[truncated 1226 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the consent-based exception and categorically prohibit persistent storage of:
- Passport and government identification numbers
- Payment-card and banking data
- Insurance and medical identifiers
- Credentials, authentication tokens, and recovery codes
- Ticket or reservation identifiers that grant account or booking access
- Exact residential addresses
-
Replace the final instruction with an unambiguous rule such as:
markdown Never store passport or government ID numbers, credentials, authentication tokens, payment or banking data, insurance or medical identifiers, ticket or reservation access codes, or exact home addresses. If asked, explain that persistent memory is unsuitable and retain only a redacted or coarse summary.-
Store only coarse, decision-relevant values, such as a neighborhood rather than an exact address, a broad budget band rather than payment information, or an accessibility preference rather than an insurance identifier.
-
Validate and redact memory content before every write. Detect common secret and identifier patterns and reject the write rather than relying solely on conversational consent.
-
Create the memory directory and file with owner-only permissions where supported, such as directory mode
0700and file mode0600. -
Add explicit retention and deletion controls, including a user-visible command to inspect, correct, clear, or permanently delete stored memory.
-
Reconcile
setup.mdwithSKILL.md:199-201so that all documentation states the same unconditional prohibition.
-
