T09 · Insecure Skill Coding Practices
- Location
data.json:3- Finding
Plaintext Operational Metadata Distributed with the Skill
- Content
View full analysis
Vulnerability Details
File Location:
data.json, lines 3–256
Vulnerability Type: Plaintext sensitive operational data exposure
Risk Level: LowVulnerable Data
json { "timestamp": "2026-01-26T22:05:08.819698", "date": "2026-01-26", "category": "tech", "task": "integration_setup", "hours": 2.0, "notes": "Toast API" }, { "timestamp": "2026-01-26T22:05:08.888779", "date": "2026-01-26", "category": "tech", "task": "integration_setup", "hours": 1.5, "notes": "Microsoft Graph (Outlook)" }, { "timestamp": "2026-01-26T22:05:09.081477", "date": "2026-01-26", "category": "tech", "task": "automation_created", "hours": 1.0, "notes": "Morning Briefing cron" }, { "timestamp": "2026-01-26T22:05:09.244674", "date": "2026-01-26", "category": "research", "task": "competitive_analysis", "hours": 3.0, "notes": "Bulla Gastrobar deep dive" }, { "timestamp": "2026-01-26T22:05:09.631587", "date": "2026-01-26", "category": "sales", "task": "pipeline_review", "hours": 0.5, "notes": "Pipedrive analysis" }Technical Analysis
The distributed data file contains 30 timestamped operational records in plaintext. These records disclose third-party integrations, scheduled automation names, business research subjects, communication tooling, sales systems, and project-related activities.
The records are not required for the application to function. The tracker can operate with an empty data structure such as
{"entries": []}. Shipping runtime-generated operational history in the package therefore creates unnecessary information exposure.No credentials, authentication tokens, or direct secrets were identified in the reviewed data. Exploitation requires access to the project directory, repository, release archive, backup, or another copy of the package.
Attack Path
- An attacker obtains read a ...[truncated 1092 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace the distributed file with a clean initial state:
json { "entries": [] } -
Exclude runtime-generated
data.jsonfiles from version control and release archives, while retaining a sanitized template such asdata.example.json. -
If demonstration records are necessary, use clearly synthetic organization names, timestamps, integrations, and activities.
-
Add a release-stage check that detects populated runtime data, credentials, tokens, personal information, and internal project names.
-
Store user-generated records in a user-specific application data directory rather than inside the installed Skill directory.
-
Restrict file permissions where records may contain confidential descriptions or notes.
-
Document data-retention, backup, sanitization, and deletion procedures for users.
-
