T09 · Insecure Skill Coding Practices
- Location
scripts/medication_commander.py:137- Finding
Insecure Plaintext Storage of Medication Adherence Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local medication organizer whose sensitive adherence storage is disclosed and purpose-aligned, but users should understand it stores health-related records in plaintext.
Install only if you are comfortable keeping medication adherence history in a local plaintext file under your home directory. On shared, backed-up, or synced machines, consider restricting file permissions, deleting the adherence file when no longer needed, or avoiding the adherence feature.
scripts/medication_commander.py:137Insecure Plaintext Storage of Medication Adherence Data
The skill documentation exposes file read/write behavior via the adherence feature storing data in a user home directory, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agent ecosystem, undeclared filesystem access weakens least-privilege guarantees and can let the skill read or modify files beyond what a reviewer or runtime policy expects.
The documentation explicitly states that medication adherence records are stored persistently in a predictable file under the user's home directory, but provides no warning that this data is sensitive health information. In the context of a medication-management skill, these records can reveal medical conditions and treatment patterns, increasing privacy risk if the file is exposed through shared accounts, backups, logs, or weak local permissions.
The script persists adherence history to a predictable file in the user's home directory containing medication names, dosing times, and taken/missed status, which is sensitive health information. In a medication-management context this is especially sensitive, and the code provides no notice, consent flow, permission hardening, or retention controls, increasing the chance of unintended local disclosure on shared systems or through backups/sync.
The script loads user-supplied JSON medication lists, which inherently contain sensitive personal health data, but the usage text and argument help do not warn users about handling or exposing this information. For a medication-management tool, this is a meaningful privacy disclosure gap in the user-facing interface.
No suspicious patterns detected.