T09 · Insecure Skill Coding Practices
- Location
SKILL.md:65- Finding
Plaintext Storage of Sensitive Customer, Pet Health, and Billing Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 65–119
Vulnerability Type: Sensitive data stored in unprotected local JSON files
Risk Level: MediumEvidence
text ### Pet Owner ProfileOwnerID: OWN001 Name: John Smith Phone: +1-555-1234 Email: john@example.com Address: 123 Main St, Anytown, USA Emergency Contact: Jane Smith (wife) +1-555-5678 Created: 2026-06-15
text ### Pet ProfilePetID: PET001 Name: Buddy Species: Dog Breed: Golden Retriever Age: 3 years Gender: Male (neutered) Weight: 30kg Vaccination Status: Up-to-date (last: 2026-01-15) Special Instructions: Needs medication after meals (see meds list) Medical Conditions: None OwnerID: OWN001 Created: 2026-06-15
text ### Boarding ReservationReservationID: RES20250620001 PetID: PET001 CheckIn: 2026-06-20 10:00 CheckOut: 2026-06-25 16:00 Package: Premium ($45/night, includes daily walks + grooming) Status: Confirmed TotalNights: 5 Subtotal: $225 Tax: $22.50 Total: $247.50 Notes: "First time boarding, may be anxious"
text ### Daily Care LogLogID: LOG20250621001 PetID: PET001 Date: 2026-06-21 Activities: - 08:00: Fed 500g Royal Canin (ate all) - 09:00: 30min walk (potty training, pooped normally) - 13:00: Medication (antibiotic, after lunch) - 18:00: Fed 500g Royal Canin + supplements - 19:00: 20min playtime in yard HealthNotes: "Energetic, good appetite, no diarrhea" StaffInitials: AS
text ## Pricing Calculator Base rates (example): - Standard boarding: $30/night (dogs), $25/night (cats) - Deluxe boarding: $45/night (dogs), $35/night (cats) - Luxury suite: $65/night (dogs), $50/night (cats) Add-on services: - Extra walk: $10/session - Grooming: $25/session - Medication administration: $5/day - Special diet preparation: $8/day Tax: 10% (adjustable by location) ## File Storage All data stored in `~/.openclaw/p ...[truncated 2925 chars]- Remediation
View remediation
Remediation Suggestions
- Require creation of
~/.openclaw/pet-boarding-data/with owner-only permissions, such as mode0700, and each data file with mode0600. Verify permissions after creation and reject unsafe ownership or symbolic links. - Encrypt sensitive records at rest using an authenticated encryption scheme. Store encryption keys in an operating-system credential store or dedicated secrets manager rather than alongside the JSON files.
- Apply data minimization. Store only information necessary for boarding operations and avoid retaining complete payment credentials. Use a compliant payment provider and retain only non-sensitive transaction references.
- Define role-based access controls where multiple staff members use the system. Separate permissions for medical records, billing, administration, and routine care logs.
- Add integrity protection, atomic writes, schema validation, and audit logging for changes to medication instructions, reservations, and billing records.
- Establish explicit retention and secure-deletion policies for expired reservations, billing records, contact information, and health notes.
- Prevent accidental disclosure through logs, generated responses, exports, backups, and synchronization services. Redact sensitive fields by default.
- Document secure backup requirements, including encryption, access restrictions, restoration testing, and deletion from retired backup media.
- Require creation of
