T09 · Insecure Skill Coding Practices
- Location
skill.md:75- Finding
Uncontrolled Transmission of Sensitive Session and Memory Data to a Third-Party API
- Content
View full analysis
Vulnerability Details
File Location:
skill.md, lines 75-93; related privacy and context-handling statements at lines 652-658 and 716-729
Vulnerability Type: Sensitive data exposure through external API processing
Risk Level: MediumVulnerable Documentation Snippet:
markdown #### Recommended: Direct generation via SkillBoss API Hub This skill calls SkillBoss API Hub (`/v1/pilot`) directly for AI generation. Set `SKILLBOSS_API_KEY` and run: ```bash python3 scripts/generate.py --todayThe script will:
- Gather context from today's session logs
- Call
https://api.heybossai.com/v1/pilotwithtype=chat - Save the generated diary entry automatically
text Related claims and behavior include: ```markdown ## Privacy - All entries stored locally in your memory directory - Privacy level controls what's included - Export before sharing anything - `.gitignore` excludes config.json and exports by defaultmarkdown - **Context Awareness:** Reads recent session logs and existing memory files for contextTechnical Analysis
The documented generation workflow reads recent session logs and existing memory files and then calls the external endpoint
https://api.heybossai.com/v1/pilot. These sources can contain confidential conversations, personal information, project details, user quotations, relationship notes, decisions, or credential-like strings.The documentation does not define an explicit consent boundary, data-field allowlist, secret-detection mechanism, redaction process, payload-size limitation, payload preview requirement, or third-party retention and deletion policy. The available
--emit-taskoption can expose a payload for review, but it is optional rather than a mandatory safeguard.The statement that all entries are stored locally only describes generated entry storage and does not clearly disclose that source context is transmitted to an extern ...[truncated 2370 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit, informed opt-in before sending any session or memory content to an external API. Keep remote generation disabled by default.
- Clearly disclose which files and fields are read, which data is transmitted, the destination hostname, and the provider's retention and deletion policies.
- Apply data minimization through a strict allowlist. Do not submit complete session logs or memory files when a bounded summary is sufficient.
- Run secret and sensitive-data redaction before constructing the request. Remove API keys, tokens, passwords, private keys, credentials, personal identifiers, and unrelated conversation content.
- Make payload preview and confirmation mandatory for the first request and whenever additional source files or categories are selected.
- Ensure privacy levels control both generated output and outbound source context. Document the exact filtering rules for each level.
- Provide a fully local or interactive generation mode that does not contact third-party services.
- Make memory integration opt-in, especially the
fullformat, and warn users that it duplicates potentially sensitive material. - Document request authentication, certificate verification, timeout behavior, logging controls, third-party subprocess behavior, and error handling.
- Include the referenced scripts in the auditable package so reviewers can verify file-access boundaries, request construction, redaction, credential handling, and safe persistence behavior.
- Revise the privacy section to distinguish local output storage from external processing of source context and generated content.
