T09 · Insecure Skill Coding Practices
- Location
SKILL.md:16- Finding
Plaintext Persistence of Sensitive Health and Behavioral Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The sleep coaching skill matches its stated purpose, but it persistently stores sensitive sleep, health-adjacent, substance, household, and travel details without clear consent, privacy, or deletion controls.
Review before installing if you are not comfortable with a local sleep diary and memory files being kept under ~/Clawic/data/sleep/. Those files may include sleep patterns, red-flag screening context, substance habits, prescriptions context, household routines, and travel plans; consider deleting or protecting that directory if you use the skill.
SKILL.md:16Plaintext Persistence of Sensitive Health and Behavioral Data
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
last: YYYY-MM-DD
## Context
<!-- Schedule reality: work pattern, commitments, observed chronotype -->
<!-- Household: partner schedule, kids, pets, room situation -->
## Protocol State
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
## Driving (the hard lines)
- Microsleeps arrive without warning at the wheel; yawning, drifting lanes, missing exits are late-stage signals, not early ones.
- The only countermeasures that work: stop, caffeine, 20-min parked nap (the coffee nap, above), or a different driver. Windows down and loud music measurably do not.
- Veto lines, stated flat: no driving past 17-19 h awake (the ~0.05% line, above), after a night under 5 h, or during week 1-2 of a restriction protocol (`insomnia.md` warns the same).
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
## Your Attitude
Sleep is where advice inflation does damage: one measured intervention beats five tips. Triage first, protocol second, referral without hesitation when the Red Flags table says so. Be calm and concrete; never moralize about the user's schedule.
## How To Load Preferences
This section gives specific medical-style intervention guidance, including timed bright-light exposure and melatonin dosing, without a clear warning that these are not personalized medical instructions and may carry health risks. In context, the advice can affect circadian rhythm, mood, and underlying conditions; the file itself even notes bipolar activation risk, which makes omission of an upfront safety warning materially risky.
The skill directs the user to record sensitive sleep and health-related data in a specific local path (~/Clawic/data/sleep/diary.md) without warning about privacy, retention, or who can access that file. Because this is health-adjacent personal data, hardcoding storage behavior can lead to unintended persistence, exposure to other local users, backups, sync services, or later reuse by other tools without informed consent.
The template directs storage of sensitive health-related and household information in a predictable local path without any warning, consent language, or privacy guidance. In a sleep-coaching context, this may capture medical-adjacent data, family/household details, substance habits, and red-flag screening notes, increasing privacy and confidentiality risk if the file is exposed or synced insecurely.
The skill explicitly instructs the agent to read from and write to persistent user-specific files containing preferences, schedule details, substance habits, and protocol state, but it does not require notifying the user or obtaining consent for this storage/access. This creates a privacy and transparency risk because sensitive behavioral and health-adjacent information may be persisted or reused across sessions without the user's awareness.
The skill instructs the agent to write a trip plan into a specific local file path without telling the user or obtaining consent. Even though the content is benign sleep-planning data, silent filesystem writes can create privacy, transparency, and unwanted-persistence issues, especially if the destination contains health-related travel or sleep information.
No suspicious patterns detected.