T09 · Insecure Skill Coding Practices
- Location
SKILL.md:65- Finding
Plaintext Persistence of Sensitive Personal and Medical Information
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appointment skill has a coherent purpose, but it expects to store and transmit sensitive appointment and medical-adjacent data with broader authority than its manifest clearly declares.
Review this before installing. It is not evidence of malware, but it should only be used if you are comfortable with the agent keeping appointment and provider history in local Markdown files, sending reminders through configured channels, using calendar access, and entering personal details into booking sites. Prefer explicit confirmation before any booking, cancellation, calendar update, or transmission of DOB, medical reason, address, or follow-up notes.
SKILL.md:65Plaintext Persistence of Sensitive Personal and Medical Information
SKILL.md:6Declared Tool Permissions Do Not Match Required Privileged Operations
SKILL.md:105Sensitive Booking Data May Be Submitted to Unverified External Websites
The skill is designed to collect and store sensitive personal and health-related appointment data in local markdown files without prominently warning the user. Because the stored data includes medical providers, appointment history, addresses, notes, and potentially date of birth or referrals, lack of disclosure materially increases privacy and compliance risk.
The trigger list includes broad terms such as doctor and dentist, which can cause unintended invocation in ordinary conversation. In a skill that stores sensitive medical and appointment data and may initiate web actions, accidental activation increases privacy and action-taking risk.
The skill states that online booking is handled automatically but does not clearly warn that it may submit user-provided personal data to third-party booking websites and calendar systems. Without explicit notice and consent, users may not understand that external services will receive their identifying or health-related information.
The skill instructs the agent to check and update Google Calendar despite only declaring web_search and web_fetch as allowed tools. This creates a permission/specification mismatch that can lead to unsafe assumptions, failed enforcement, or pressure to use undeclared capabilities for calendar access and modification.
The skill persistently stores appointment details, provider information, confirmation references, prep notes, and follow-up notes in plain-language files and later reuses them in reminders. In this context, the data can reveal medical conditions, treatment patterns, location history, and other sensitive personal information, making plaintext retention and replay especially risky.
The phone-script workflow instructs the agent to compile personal and potentially medical details, including name, date of birth, reason for visit, and availability, into a single message for reuse. Consolidating this information into one outbound message increases exposure if the message is misdelivered, logged, or viewed by others on the user's channel.
The structured memory design explicitly accumulates long-term appointment, provider, status, follow-up, and notes data across time. In a life-admin and health-adjacent context, such longitudinal records substantially increase harm from unauthorized access because they can expose routines, medical relationships, and historical sensitive events.
The text states that online booking requires no action beyond the initial request, yet later sections require the user to choose among providers and slots and sometimes supply required personal details. This is an active contradiction in the skill's own documentation about how autonomous the flow really is.
No suspicious patterns detected.