T09 · Insecure Skill Coding Practices
- Location
SKILL.md:301- Finding
Automatic Persistent Storage of Sensitive User Profiles Without Explicit Consent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This INTP coaching skill is generally coherent, but it directs automatic long-term storage of sensitive coaching profiles without clear consent or deletion controls.
Review before installing. Use this only if you are comfortable with the agent keeping a coaching profile across sessions; the package should be revised to make memory opt-in and user-reviewable before routine use.
SKILL.md:301Automatic Persistent Storage of Sensitive User Profiles Without Explicit Consent
The README says user conversations and growth records are saved automatically, but it does not explain consent, retention, access controls, or deletion. Because this skill handles sensitive self-reflection and possible mental-health-adjacent content, silent persistence can expose private personal data and create privacy/compliance risk.
The manifest says the skill should not trigger for vague emotions without INTP context or for non-INTP users, but the body explicitly instructs the agent to engage in both cases. This scope drift can cause unintended activation and collection of sensitive emotional or identity-related information from users outside the declared audience.
The skill presents itself as a narrow INTP coaching tool, but also advertises persistent growth records and user profiling not disclosed in the manifest description. Hidden expansion from coaching into profiling/retention undermines informed use and increases privacy risk, especially because the stored data includes personal struggles, goals, and behavior patterns.
The skill states it will save conversation history and action records for future sessions, but does not provide a clear user-facing privacy warning or consent flow. Because the content involves personal development, motivation, and potentially mental-health-adjacent disclosures, silent retention creates a meaningful privacy and trust risk.
The skill instructs persistent retention of user conversation details for reuse across sessions, creating a long-lived behavioral profile. Persistent memory of coaching conversations can expose sensitive information about mental state, goals, and habits if accessed improperly or used beyond the user's expectations.
The skill directs the agent to record key insights from user conversations into a user profile, which is a form of inferred personal data collection. Storing inferred traits and patterns is more sensitive than merely storing raw chat text because it creates enduring summaries that can influence future treatment of the user.
These instructions repeatedly direct the agent to archive sensitive profile attributes such as core problems, interests, actions, and insights, but no explicit privacy warning accompanies the collection. Repeated undisclosed profiling increases the chance that users reveal intimate data without realizing it will be retained and reused.
The defined user archive includes core problems, interests, action history, and key insights for later reuse, amounting to a structured personal profile. In the context of a coaching skill, this can reveal vulnerable patterns and sensitive self-assessments over time, increasing harm if mishandled or repurposed.
The skill makes profile recording a required behavior and then instructs storage again at conversation end, normalizing persistent collection without user control. Mandatory retention is particularly problematic here because users may disclose emotional struggles and life-direction concerns under the expectation of ephemeral coaching support.
The end-of-conversation flow requires storing key user information after the user believes the conversation is complete, yet no clear warning is given at that point. This is especially risky because closure language can imply the interaction is over while hidden retention continues in the background.
The file is entirely written in Chinese and presents fixed coach phrasing without indicating that the user can choose another language. In a conversational skill, forcing a single locale can exclude or confuse users, increase the chance of misunderstanding guidance, and reduce informed user control over the interaction.
This markdown file is entirely written in Chinese and is described as internal reference material for the intp-coach skill. There is no indication that the user can choose language/locale, nor any documented reason that the skill must operate only in Chinese, which can violate language/locale policy requirements.
Natural-language policy checks apply to all file types, including markdown. The title and description frame the skill specifically as an 'INTP Coach' based on MBTI-oriented guidance, which can impose a fixed personality/interaction framing unless the user explicitly opts into that categorization; the README does not clearly state that non-INTP users can decline or choose a different framing.
The README claims the skill will '保存对话和行动,下次继续聊' and labels it '自动执行', which expands the skill from coaching into user-data persistence. In the provided file, there is no code or implementation detail demonstrating storage behavior, so the documented behavior does not match the actual material available for review.
The repository URL points to a project name that appears unrelated to the declared INTP coaching skill, which is a software supply-chain integrity concern. A mismatched repository can mislead reviewers, hinder provenance verification, and potentially direct users to unreviewed or substituted content if they rely on the repository for updates or trust validation.
No suspicious patterns detected.