T09 · Insecure Skill Coding Practices
- Location
- SKILL.md:998
- Finding
- Plaintext Storage and Unredacted Disclosure of Vehicle and Insurance Identifiers<![CDATA[ ## Vulnerability Details **File Location**: `SKILL.md`, lines 998-1043; related collection and storage instructions at lines 129-132 and 189-199 **Vulnerability Type**: Plaintext sensitive-data storage and excessive disclosure **Risk Level**: Medium ### Vulnerable Code Snippet ```json { "emergency_info": { "vin": "1FT8W3BT0MED12345", "insurance_provider": "State Farm", "policy_number": "SF-123456789", "roadside_assistance_phone": "1-800-555-1234", "tire_size_front": "275/70R18", "tire_size_rear": "275/70R18", "tire_pressure_front_psi": 65, "tire_pressure_rear_psi": 80, "oil_type": "15W-40 CK-4 Full Synthetic", "oil_capacity": "15 quarts", "coolant_type": "Motorcraft Orange VC-3DIL-B", "def_type": "API certified DEF", "trans_fluid": "Motorcraft Mercon ULV", "tow_rating_lbs": 20000, "gvwr_lbs": 14000, "gcwr_lbs": 37000, "payload_lbs": 4300, "key_fob_battery": "CR2450", "fuel_type": "Diesel (Ultra Low Sulfur)", "fuel_tank_gallons": 48, "lug_nut_torque_ft_lbs": 165, "jack_points": "Frame rails, front and rear", "notes": "" } } ``` ```text ### Quick Access Queries Respond instantly to: - "What's my VIN?" → Return VIN - "What are my truck's tire specs?" → Tire sizes and pressures - "What oil does my truck take?" → Oil type and capacity - "Insurance info?" → Provider, policy number, phone - "Roadside assistance number?" → Phone number - "What's my tow rating?" → Tow rating, GVWR, GCWR - "Key fob battery?" → Battery type - "Lug nut torque?" → Torque spec ``` ```text ### Emergency Card Format When asked for "emergency info" or "vehicle card": ``` 🚨 Emergency Info — [Vehicle Label] ━━━━━━━━━━━━━━━━━━━━━━━━━━━ VIN: [vin] Insurance: [provider] — Policy #[number] Roadside: [phone] 🔧 Specs Tires: F:[size] R:[size] Pressure: F:[X]psi R:[X]psi Oil: [type] ([capacity]) Coolant: [type] Fuel: [type] ([tank] gal) Key fob battery: [type] 📏 Ratings Tow: [X] lbs | GVWR: ...[truncated 3011 chars]
- Remediation
- <![CDATA[ ## Remediation Suggestions 1. **Make sensitive storage explicitly opt-in** - Do not collect insurance policy numbers during ordinary vehicle setup. - Explain why each sensitive field is requested and how it will be stored. - Obtain explicit confirmation before persisting VIN or insurance information. 2. **Minimize retained information** - Store only the last four characters of a policy number unless the user specifically enables full emergency-card storage. - Avoid duplicating the VIN in both the top-level vehicle record and `emergency_info`. - Separate ordinary maintenance data from sensitive emergency information. 3. **Protect data at rest** - Store full insurance identifiers in an operating-system credential store or encrypted secrets facility rather than ordinary JSON. - If file storage is unavoidable, require owner-only file and directory permissions. - Do not include sensitive state files in routine logs, diagnostics, exports, or unencrypted backups. 4. **Redact output by default** - Display masked values such as `VIN: *************2345` and `Policy: ********6789`. - Require a separate explicit request and confirmation before showing complete values. - Avoid sending complete identifiers through group chats or other shared delivery channels. 5. **Add lifecycle controls** - Provide commands to inspect, update, export, and permanently delete sensitive fields. - Define a retention policy and periodically ask whether emergency information should remain stored. 6. **Constrain access** - Document that other Skills and workspace processes must not read the mechanic state unless authorized. - Consider placing sensitive emergency information in a dedicated file with narrower access controls than routine maintenance data. 7. **Improve network disclosure** - Before sending a VIN to NHTSA, clearly disclose that the identifier will be transmitted to an external government API. - Offer make/model/year rec ...[truncated 68 chars]
