T09 · Insecure Skill Coding Practices
- Location
SKILL.md:172- Finding
Unprotected Persistent Storage of Sensitive Health Profiles
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 172-205
Vulnerability Type: Plaintext storage of sensitive personal and health information
Risk Level: MediumThe documented workflow instructs the Agent to persist each user's demographic, health, and progress information in a Markdown file:
markdown Output recommendations ↓ Record them in the user profile (memory/user-ID/fat-loss-profile.md)markdown Each user's data is stored in `memory/{user-id}/fat-loss-profile.md` and includes: # Fat-Loss Profile ## Basic Information - Gender: - Age: - Height: - Initial weight: - Target weight: - Activity level: - Dietary preferences: - Health conditions: ## Calculation Results - BMR: - TDEE: - Target calories: ## Progress Records | Date | Weight | Body-fat percentage | Waist | Exercise | Diet score | Notes | |------|--------|---------------------|-------|----------|------------|-------|Technical Analysis
The workflow stores health conditions, body measurements, dietary preferences, and behavioral records in a predictable plaintext path. It does not require:
- Explicit user consent before persistence
- Data minimization
- Retention or automatic deletion limits
- File access restrictions
- Encryption at rest
- Separation between different users
- Validation or canonicalization of
{user-id}before path construction
If the runtime directly interpolates a user-controlled identifier into the documented path, path separators or traversal sequences could cause the profile to be written outside the intended user directory. Even without path traversal, predictable plaintext profile files can expose sensitive information to other processes or users that can read the Agent's storage directory.
No profile-writing implementation is present in
scripts/calculate.py; exploitation therefore depends on the host Agent following the documented storage workf ...[truncated 1083 chars]- Remediation
View remediation
Remediation Suggestions
- Make profile persistence opt-in and clearly disclose which fields will be stored.
- Store only information required for the current coaching function; avoid retaining free-form health notes by default.
- Replace user-provided path components with server-generated opaque identifiers.
- Reject path separators, traversal sequences, absolute paths, null bytes, and unexpected identifier characters.
- Resolve and canonicalize the destination path, then verify that it remains beneath the designated profile directory before writing.
- Apply restrictive file permissions so profiles are accessible only to the Agent's service account.
- Encrypt sensitive records at rest when the host environment supports it.
- Define retention periods and provide profile inspection, export, and deletion controls.
- Separate users at the storage and authorization layers rather than relying only on directory naming.
- Avoid writing profiles when the runtime cannot provide appropriate privacy and access-control guarantees.
