Back to skill

Security audit

Orlando

Security checks for vulnerabilities and agentic risk

Overview

This Orlando guide is mostly coherent, but its optional persistent memory could retain sensitive personal details in plaintext and contains a conflicting exception for highly sensitive data.

Review this before installing if you plan to use memory. The skill can be used statelessly, which avoids the main risk. If you enable ~/orlando/memory.md, do not ask it to remember passport numbers, payment details, insurance IDs, ticket or reservation access codes, or exact home addresses; periodically inspect and delete that file if it contains more detail than you intended.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
setup.md:64
Finding

Plaintext Persistence of Sensitive Personal and Financial Data

Content
View full analysis

Vulnerability Details

File Location: setup.md:64-71
Vulnerability Type: Sensitive data stored in plaintext persistent memory
Risk Level: Medium

Vulnerable Code Snippet

markdown
Keep `~/orlando/memory.md` lightweight and useful:
- activation preference for Orlando topics
- current mode, timeline, and preferred base area
- park priorities, lodging pattern, or move shortlist
- major family, school, healthcare, or commute constraints
- open loops such as district comparison, park strategy, or Florida filing tasks

Do not store passports, ticket numbers, payment details, insurance IDs, or exact home addresses unless the user explicitly asks for that behavior.

Technical Analysis

The final instruction creates an exception that permits passport information, ticket numbers, payment details, insurance identifiers, and exact home addresses to be stored when a user requests it. The designated storage mechanism is ~/orlando/memory.md, a persistent plaintext Markdown file.

The Skill specifies no encryption, restrictive file permissions, data minimization controls, automatic redaction, retention period, secure deletion process, or validation preventing secrets from entering memory. User consent does not mitigate the technical risks of storing authentication-adjacent, financial, healthcare, identity, and precise-location information in plaintext.

This instruction also conflicts with the stronger privacy statement in SKILL.md:199-201, which states that the Skill does not store passport numbers, payment data, or health-insurance identifiers. The contradictory policy could cause the Agent to apply the weaker rule and persist information users reasonably expect never to be stored.

Attack Path

  1. The Skill is activated for an Orlando-related conversation.
  2. Persistent memory is enabled under ~/orlando/memory.md.
  3. A user, malicious prompt, or untrusted copied content asks the Agent to remember a passport number, payment detail, in ...[truncated 1226 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the consent-based exception and categorically prohibit persistent storage of:

    • Passport and government identification numbers
    • Payment-card and banking data
    • Insurance and medical identifiers
    • Credentials, authentication tokens, and recovery codes
    • Ticket or reservation identifiers that grant account or booking access
    • Exact residential addresses
  2. Replace the final instruction with an unambiguous rule such as:

markdown
Never store passport or government ID numbers, credentials, authentication
tokens, payment or banking data, insurance or medical identifiers, ticket or
reservation access codes, or exact home addresses. If asked, explain that
persistent memory is unsuitable and retain only a redacted or coarse summary.
  1. Store only coarse, decision-relevant values, such as a neighborhood rather than an exact address, a broad budget band rather than payment information, or an accessibility preference rather than an insurance identifier.

  2. Validate and redact memory content before every write. Detect common secret and identifier patterns and reject the write rather than relying solely on conversational consent.

  3. Create the memory directory and file with owner-only permissions where supported, such as directory mode 0700 and file mode 0600.

  4. Add explicit retention and deletion controls, including a user-visible command to inspect, correct, clear, or permanently delete stored memory.

  5. Reconcile setup.md with SKILL.md:199-201 so that all documentation states the same unconditional prohibition.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · memory-template.md (reported line 15)May include surrounding context.

md
integration: pending | done | declined

## Context
<!-- What you know about their Orlando situation -->
<!-- Visitor, conference traveler, resident, relocator, remote worker, family -->
<!-- Trip dates, move timeline, budget, and anchors such as parks, airport, or Downtown -->

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
## What Usually Fails

- Beach day on a partial departure day
- Springs day without checking reservations, capacity, or storm forecast
- Trying to combine a beach, an outlet mall, and Disney Springs in one day

## Best Add-On by Visitor Type

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · day-trips.md (reported line 23)May include surrounding context.

md
## What Usually Fails

- Beach day on a partial departure day
- Springs day without checking reservations, capacity, or storm forecast
- Trying to combine a beach, an outlet mall, and Disney Springs in one day

## Best Add-On by Visitor Type

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template explicitly instructs creation and ongoing maintenance of a persistent memory file containing potentially sensitive personal data, including trip dates, move timelines, budgets, family status, commute corridors, school districts, and location anchors. There is no minimization guidance, consent check, retention limit, or warning against storing sensitive or unnecessary personal information, which creates privacy and profiling risk if the memory is over-collected, exposed, or reused outside the user's expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation rule is overly broad because it triggers on any mention of Orlando or Central Florida, regardless of user intent. In a multi-skill environment, this can cause unnecessary interception of unrelated conversations, collection of context the user did not intend for this skill, and misrouting of assistance toward this domain.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · theme-parks-universal.md (reported line 30)May include surrounding context.

md
- Paying for park-to-park without caring about the Hogwarts Express or cross-park flow
- Staying far away to save on hotel rate, then losing time to traffic and parking
- Adding Epic Universe without cutting something else
- Assuming Universal is meaningfully cheaper once add-ons are included

## Best Fit

Static analysis

No suspicious patterns detected.