T09 · Insecure Skill Coding Practices
- Location
SKILL.md:124- Finding
Potential Sensitive Conversation Data Exported to Notion Without Mandatory Redaction
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill openly archives conversation memories to the user's Notion workspace, but it can process broad chat history and preserve sensitive technical details without mandatory preview or redaction.
Review before installing. Use this only if you are comfortable granting the agent access to conversation content and allowing it to write extracted memories into Notion. Prefer current-session or explicitly selected conversations, review entries before upload, and do not archive secrets, credentials, private keys, session cookies, .env values, or sensitive internal URLs.
SKILL.md:124Potential Sensitive Conversation Data Exported to Notion Without Mandatory Redaction
The skill begins by describing retrieval of past conversation history and storage in Notion, but it does not require an upfront privacy notice or explicit informed consent before accessing and transmitting that data to a third-party service. Because the workflow includes external export and database creation, lack of disclosure materially increases the risk of silent data exfiltration from chat history.
The skill explicitly instructs the agent to retrieve past conversation history, derive atomic memory entries, and write them into an external Notion database, including valuable user facts and context. This creates a built-in mechanism for collecting and exporting potentially sensitive personal, project, and operational information outside the original chat boundary.
These instructions direct the agent to fetch recent chats, use search over conversation history, and paginate for comprehensive archival, effectively turning the skill into a chat-history export pipeline. The context makes this especially risky because the workflow normalizes bulk retrieval across multiple conversations, increasing the chance that unrelated sensitive discussions are copied into Notion.
Instructing the agent to preserve code snippets, commands, config values, and URLs verbatim significantly raises the chance of storing API keys, internal endpoints, tokens, credentials, or sensitive infrastructure details in Notion. Verbatim retention is particularly dangerous in a memory-export skill because secrets that appeared transiently in chat become durable, searchable records in an external system.
The trigger phrases are broad enough to match ordinary requests about reviewing or recording prior discussion, which can invoke a workflow that exports conversation-derived data to Notion without a narrowly scoped confirmation. In this skill, unintended activation is more dangerous because the side effect is external persistence of sensitive memories rather than a local, reversible action.