T09 · Insecure Skill Coding Practices
- Location
SKILL.md:126- Finding
Persistent Storage of Sensitive Mental-Health Data Without Privacy Safeguards
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:126-140andSKILL.md:363-368
Vulnerability Type: Sensitive health-data persistence without consent, minimization, or retention controls
Risk Level: MediumVulnerable Code
SKILL.md:126-140:markdown Over time, remember these preferences (via OpenClaw memory): **Schedule & Energy:** - Peak focus hours (morning person vs. night owl) - Typical energy patterns throughout the day - Best times for deep work vs. shallow tasks **Task Management:** - Preferred number of daily priorities (1-3 recommended) - Task/note storage location (files, apps, directories) - Preferred reminder frequency and channels **ADHD Profile:** - Diagnosed or suspected ADHD - Current treatments (medication, therapy) - for context onlySKILL.md:363-368:markdown ### Memory Usage: - Store user preferences and patterns - Remember what strategies have worked - Track routine adherence over time - Note energy patterns and triggersTechnical Analysis
The skill directs the agent to persist diagnosis status, medication or therapy information, behavioral patterns, routine adherence, energy patterns, and triggers in OpenClaw memory. Diagnosis and treatment details constitute sensitive health information, while behavioral patterns and triggers can create a detailed personal profile.
These instructions do not require explicit informed consent before persistence, distinguish session-only context from long-term memory, limit collection to information strictly necessary for the requested task, define a retention period, restrict subsequent access, or provide inspection and deletion controls. Consequently, information disclosed during an ordinary productivity conversation may be retained beyond the session without the user understanding the persistence implications.
This is an insecure configuration and data-handling pra ...[truncated 2068 chars]
- Remediation
View remediation
Remediation Suggestions
- Default all health-related information to session-only processing and prohibit persistent storage unless it is essential to a user-requested feature.
- Obtain explicit, informed, and granular opt-in consent before saving diagnosis, medication, therapy, triggers, or other health-related details.
- Remove diagnosis and treatment information from the default “preferences to learn” list. Persist only low-sensitivity operational preferences, such as preferred reminder timing or checklist style.
- Present the exact information proposed for storage and explain why it is needed, how long it will remain, and which components may access it.
- Define short retention periods and automatic expiration for saved preferences.
- Provide user-accessible commands to inspect, correct, export, and permanently delete stored information.
- Apply access controls that isolate memory by user and prevent unrelated skills or sessions from retrieving sensitive records.
- Encrypt sensitive records at rest and in transit where persistence is explicitly authorized.
- Avoid storing free-form conversation excerpts; use narrowly scoped fields containing the minimum necessary data.
- Add an instruction such as:
markdown Do not store diagnoses, medication, therapy details, crisis disclosures, emotional triggers, or other health information in persistent memory. Treat this information as session-only unless the user explicitly requests storage after receiving a clear explanation of its purpose and retention.
