T09 · Insecure Skill Coding Practices
- Location
setup.md:21- Finding
Undeclared Persistent Write Outside the Documented Storage Boundary
- Content
View full analysis
Vulnerability Details
File Location:
setup.md, lines 21-28
Vulnerability Type: Undeclared external memory persistence and inconsistent storage boundaries
Risk Level: Mediummarkdown ### 2. Learn how this should activate Early in the conversation, learn when this should show up: - whenever they talk about tasks, todos, follow-ups, or commitments - only when they ask explicitly - only for selected work areas or projects If they want ongoing help, save that activation preference in their main memory so the skill appears in future sessions when it should.This instruction conflicts with the storage boundary documented in
SKILL.md, which states that memory lives in~/task-list/and that the Skill does not access files outside that directory for storage.Technical Analysis
The setup workflow directs the agent to save an activation preference in an unspecified “main memory.” This creates persistent, cross-session behavior outside the Skill's declared
~/task-list/workspace. The external memory location, retention policy, inspection mechanism, and deletion procedure are not defined.Although the user must indicate that ongoing assistance is wanted, the Skill does not require separate, explicit consent immediately before writing to this broader memory facility. The mismatch between implemented instructions and the privacy declaration prevents users from accurately understanding or controlling where their preferences are retained.
The issue does not provide arbitrary code execution, elevated operating-system privileges, or network access. Its scope is limited to persistent task-management preferences and future Skill activation behavior.
Attack Path
- A user requests ongoing task-list assistance.
- The Skill interprets that request as authorization to save an activation preference.
- The agent writes the preference to an unspecified main-memory facility outside
~/task-list/.
...[truncated 819 chars]
- Remediation
View remediation
Remediation Suggestions
- Store activation preferences exclusively in
~/task-list/memory.md, consistent with the declared storage boundary. - If integration with agent-wide memory is necessary, disclose the exact storage scope and purpose before any write occurs.
- Require separate, explicit opt-in consent immediately before writing to external or global memory.
- Document how users can inspect, update, revoke, and delete the persistent activation preference.
- Update the
SKILL.mdSecurity and Privacy section so it accurately lists every storage location used by the Skill. - Keep task contents and unrelated personal information out of global memory; retain only the minimum activation setting required.
- Add a clear fallback in which declining global-memory integration leaves the Skill manually invokable and stores nothing outside
~/task-list/.
- Store activation preferences exclusively in
