T09 · Insecure Skill Coding Practices
- Location
SKILL.md:4- Finding
Sensitive Pay Stub Data May Be Uploaded Without Mandatory Consent or Redaction
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 4 and 10-12; lines 96-98
Vulnerability Type: Sensitive-data disclosure caused by insufficient upload safeguards
Risk Level: MediumVulnerable Code Snippet
markdown description: Extract structured data from pay stubs and earnings statements — employer, employee, pay period, gross/net pay, taxes, deductions, and YTD totals — as typed JSON. Ideal for income verification and lending. Per-field confidence flags. PII redaction built in. Free 2,000 pages/month.markdown Turn pay stubs and earnings statements into clean, typed JSON — employer, employee, pay period, gross and net pay, tax withholdings, deductions, and year-to-date totals — with a `needs_review` flag on every field. Built for income verification, where a misread number has real consequences. > This skill instructs the agent to POST documents to `https://api.deepread.tech` and poll for results. No system files are modified.markdown ## Redact Before Sharing Pay stubs carry names, partial SSNs, and bank details. Redact with `deepread-pii` before sending externally: `clawhub install uday390/deepread-pii`Technical Analysis
The skill explicitly instructs an agent to upload pay stubs to an external service. Such documents can contain employee names, addresses, partial Social Security numbers, bank details, compensation, tax withholding, and deduction information.
Although the external transmission is disclosed and is integral to the service, the instructions do not require explicit user confirmation immediately before transmission. They also do not enforce redaction before uploading. The metadata claims that PII redaction is “built in,” while the later guidance directs users to install a separate redaction skill. This inconsistency may cause users or agents to assume that sensitive fields are automatically removed when no such mechanism is demonstrated in the audite ...[truncated 1646 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit, informed user confirmation immediately before every document upload.
- Clearly identify the destination domain and enumerate the categories of data that will be transmitted.
- Implement local, mandatory redaction of unnecessary PII before transmission rather than relying on optional guidance.
- Remove the statement that PII redaction is “built in” unless redaction is technically enforced and documented.
- Apply data minimization by sending only pages or fields necessary for the requested extraction.
- Document the provider’s retention period, deletion mechanism, subprocessors, geographic processing, encryption controls, and secondary-use policy.
- Offer a preview showing the redacted document and require approval before upload.
- Ensure logs, temporary files, and error reports do not retain document contents or extracted sensitive fields.
