T09 · Insecure Skill Coding Practices
- Location
SKILL.md:24- Finding
Overbroad Plaintext Persistence of Potentially Sensitive User Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is meant to preserve context across compaction, but it does so by broadly and persistently recording user messages and recovering old memory without clear limits or consent.
Review before installing. This skill may be useful for long sessions, but assume it can retain names, paths, URLs, IDs, preferences, decisions, and possibly whole messages in local memory files. Do not use it around secrets, credentials, regulated personal data, confidential customer data, or shared workspaces unless you add explicit opt-in, redaction, retention limits, and task-scoped recovery.
SKILL.md:24Overbroad Plaintext Persistence of Potentially Sensitive User Data
SKILL.md:35Persistent Memory Poisoning Through Unsanitized Recovery of User-Controlled Content
SKILL.md:57Overbroad Historical Memory Access During Automatic Recovery
These instructions require writing user-provided details to SESSION-STATE.md before responding, but provide no notice, consent flow, or sensitivity filter. That creates a direct risk of silently retaining personal, confidential, or security-relevant data in persistent storage where it may later be exposed to other skills, users, or sessions.
The working-buffer mechanism persistently logs every exchange after a context threshold, which amounts to broad transcript capture without user awareness. Because it stores both user messages and response summaries, it can accumulate sensitive content at scale and extend the exposure window well beyond the active conversation.
Appending every exchange to a working-buffer file creates a durable conversation log that is broader than the stated goal of preserving critical task state. In the context of an always-on skill, this materially increases the chance of sensitive data collection, cross-context leakage, and later unauthorized reuse during recovery or other memory operations.
Describing the skill as an always-active behavioral mechanism creates no clear activation boundary, so it can influence routine interactions far beyond a narrow memory-management use case. In practice, that broad scope increases the chance of unintended file writes, silent persistence, and interference with normal user expectations about ephemeral conversation.
The instruction to act on every incoming message is overly broad and effectively turns all user input into potential logging triggers. That makes the behavior hard to contain and increases the likelihood that sensitive or irrelevant content is captured and persisted without contextual necessity.
The WAL flow instructs the agent to continuously extract and persist corrections, preferences, decisions, and specific values from user messages. This creates a natural-language data retention risk because unstructured conversation often contains credentials, personal data, internal paths, or business-sensitive context that may be logged without discrimination.
The recovery workflow instructs the agent to mine prior logs, daily files, and search tools to reconstruct context from stored user data. While intended to improve continuity, it also increases the likelihood of resurfacing old sensitive material into a new context, including cases where the user did not expect prior content to be recalled or reprocessed.
No suspicious patterns detected.