T09 · Insecure Skill Coding Practices
- Location
SKILL.md:17- Finding
Privacy-Unsafe External Indexing of Session Transcripts
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 17-25
Vulnerability Type: External processing of potentially sensitive session data through an insecure default configuration
Risk Level: MediumVulnerable Code
json { "memorySearch": { "enabled": true, "provider": "voyage", "sources": ["memory", "sessions"], "indexMode": "hot", "minScore": 0.3, "maxResults": 20 } }Technical Analysis
The recommended configuration enables real-time indexing of persistent memory and past conversation transcripts while selecting Voyage AI as the embedding provider. Using a remote embedding provider generally requires relevant source content to be transmitted to that provider for processing.
Session transcripts may contain personal information, confidential project details, authentication material accidentally pasted into conversations, or other sensitive context. The Skill does not require informed user consent before enabling session indexing, recommend data classification or redaction, explain third-party retention considerations, or limit indexing to curated memory files.
Although the Skill mentions a local provider later in the document, the privacy-preserving option is not the recommended default. This is an insecure configuration practice because it combines broad data collection, continuous indexing, and external processing without sufficient safeguards.
Attack Path
- A user follows the Quick Setup instructions without recognizing the privacy implications.
- The user enables
sources: ["memory", "sessions"], including historical conversation transcripts in the indexing scope. - The
indexMode: "hot"setting causes new or updated content to be indexed continuously. - The configured remote provider processes transcript-derived content to generate embeddings.
- Sensitive information contained in conversations may consequently leave the local envi ...[truncated 928 chars]
- Remediation
View remediation
Remediation Suggestions
-
Use privacy-preserving defaults:
json { "memorySearch": { "enabled": true, "provider": "local", "sources": ["memory"], "indexMode": "hot", "minScore": 0.3, "maxResults": 20 } } -
Make session-transcript indexing an explicit opt-in rather than including it in the Quick Setup configuration.
-
Before enabling a remote provider, clearly disclose that indexed content may be transmitted to and processed by a third party.
-
Require users to review the provider's retention, deletion, regional processing, and model-training policies before activation.
-
Add filtering and redaction guidance for credentials, access tokens, personal data, financial information, and confidential project material.
-
Apply data minimization by indexing curated memory content only. Exclude raw sessions unless they are required for a documented use case.
-
Document procedures for deleting embeddings, rebuilding the index after redaction, and disabling external indexing.
-
Recommend separate consent and configuration controls for each source so users can independently enable
memoryandsessions.
-
