T09 · Insecure Skill Coding Practices
- Location
memory/bigseed-data/seeds.json:4- Finding
Personal Diary Data and Local Media Paths Included in the Distributed Artifact
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This journaling skill mostly matches its stated purpose, but it ships diary-like personal data and enables sensitive recurring summaries without well-supported privacy controls.
Review this carefully before installing. The core script does not show malicious code or remote payload execution, but the package should be cleaned of bundled diary data and should add real delete/disable controls before handling private memories. Treat weekly chat summaries as sensitive disclosure because they can reveal facts inferred from your journal even when raw records remain local.
memory/bigseed-data/seeds.json:4Personal Diary Data and Local Media Paths Included in the Distributed Artifact
The skill instructs the agent to persist user data by invoking a Python script that writes files under memory/bigseed-data/, but the manifest declares no explicit tool scope or allowed-tools restrictions. This creates an authorization ambiguity: a runtime may permit broader file-writing behavior than intended, and reviewers/users cannot verify the exact write boundaries from the manifest.
The weekly workflow proactively compiles sensitive personal seed data into summaries, inferred portraits, and stories, then pushes them into chat. This increases exposure of highly personal information beyond the local store and creates disclosure risk through notification surfaces, chat retention, account compromise, or delivery to the wrong recipient.
The privacy notice claims original seed data stays local and is never uploaded externally, yet the weekly workflow generates summaries, portraits, and stories from that data and pushes them to Feishu chat. Even if raw records are not sent verbatim, derived content can still disclose sensitive personal facts, making the notice materially misleading and undermining informed consent.
The skill tells users they can say 'delete this seed,' but no documented delete command or workflow exists in the tool interface. This can cause users to rely on a privacy control that is not actually implemented, resulting in retention of sensitive diary content they believed had been removed.
The save triggers include common conversational phrases such as '刚想到' and '突然想起', which can appear in ordinary chat without a real intent to store diary data. In a skill that captures intimate personal reflections, accidental activation can silently persist sensitive content the user did not mean to record.
The trigger-word list is broad and not tightly scoped, covering everyday phrases for story generation and recall features without sufficient disambiguation rules. Because this skill processes sensitive journaling data and can generate or push derived personal content, ambiguous activation increases the chance of unintended data use and disclosure.
The prompt template explicitly instructs automatic extraction of recent personal data and inferred profile information for announcement. Automated inference about habits, emotions, and life patterns can reveal sensitive attributes and amplify privacy harm if surfaced without granular consent or content controls.
The add command stores highly personal diary content to a local JSON file and also echoes part of that content to stdout immediately after saving. In a journaling/memoir skill, users are especially likely to enter sensitive personal information, so writing it unencrypted and displaying it in terminal output can expose private data through shared machines, shell history captures, terminal logs, screenshots, or redirected output.
The story export command emits full seed records and portrait data as JSON to stdout, which can disclose intimate personal data when viewed in a terminal, piped to other tools, logged by wrappers, or captured in CI/agent execution logs. Because this skill is specifically designed to build user profiles and life stories from personal memories, the exported data is likely to be unusually sensitive and rich in identifying details.
The skill states users can disable weekly pushes at any time, but no command or subscription-management workflow is documented to do so. That mismatch can lead to ongoing unsolicited delivery of sensitive personal summaries even after users believe they have opted out.
The natural-language content in this JSON file is entirely in Chinese, including user-facing content and tags, with no indication that language selection is optional or that the skill is explicitly region-specific. Under the stated policy, a fixed language/locale without user opt-in or documented justification can be a policy violation.
Natural-language strings in the top-level documentation are presented only in Chinese, and the CLI help text throughout the file follows the same pattern. Under the language policy rule, forcing a single language without offering choice or documenting the locale constraint can be a policy violation.
No suspicious patterns detected.