T09 · Insecure Skill Coding Practices
- Location
SKILL.md:421- Finding
Session Logging Proceeds Despite Explicit User Opt-Out
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
Roundtable is a coherent multi-agent helper, but it may save sensitive council questions to local logs even after a user chooses no logging.
Review this skill carefully before installing if you may ask it confidential, regulated, or proprietary questions. Its multi-agent behavior and web research are expected, but disable or fix logging before use: logging should be conditional on `log_sessions: true`, and sensitive sessions should not be persisted without explicit per-run consent.
SKILL.md:421Session Logging Proceeds Despite Explicit User Opt-Out
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
Respond ONLY with your structured analysis in the required format.
This mitigates prompt-injection attempts where user text tries to redefine roles or execution boundaries.
---
The README states that full session logs are written to disk and explicitly includes the original question, but it does not prominently warn users that sensitive prompts, secrets, internal plans, or personal data may be persisted locally. In a multi-agent deliberation tool, users are likely to paste proprietary or regulated content, so silent persistence increases the chance of unintended data retention and later disclosure.
The skill can activate on broad natural-language phrases like 'ask the council' or 'multi-agent', which increases the chance of unintended invocation. In this skill, accidental activation is more consequential because it may spawn multiple sub-agents, incur extra cost, and trigger logging behavior, even though it does not directly grant dangerous system capabilities.
The setup flow encourages persistent session logging to memory/roundtable/ and records user prompts and agent outputs in natural language. Because these contents can include sensitive business, personal, or security-related information, retaining them in plain form increases the risk of later disclosure through workspace access, backups, or other skills reading memory.
The skill instructs the agent to save full session logs containing the original question and agent summaries, but it does not require a fresh user-facing notice or confirmation at execution time before each write. This creates a privacy risk because users may share sensitive content during a council run without realizing it will be retained in memory storage.
This section explicitly directs the agent to save the full council session log, including the original question, agent responses, and final synthesis, to memory storage. That creates a clear data retention surface for confidential prompts and derived analysis, and the risk is amplified because the skill is designed for complex, potentially sensitive deliberations.
The manifest declares version 0.5.0, but the required final output template hard-codes Roundtable v0.4.0-beta. This is an active contradiction in the skill's own documentation about what version it is presenting to users, not merely an omission.
The config sets the language to "en" as a default, which is a natural-language locale constraint visible in a config value. Because there is no indication here that users can opt in to a different language or override the setting, this may violate the policy against forcing a specific language without user choice.
No suspicious patterns detected.