T09 · Insecure Skill Coding Practices
- Location
src/utils/log.js:25- Finding
Automatic Persistent Storage of Personal and Behavioral Data
- Content
View full analysis
- Remediation
View remediation
` or `--save-results`, and clearly disclose what fields will be retained. 3. Minimize stored content by excluding user identifiers, SEC_UID values, nicknames, IP-region labels, and comment text unless they are required for the stated purpose. 4. Create files with restrictive permissions, for example: ```js await fs.promises.mkdir(path.dirname(outputFilename), { recursive: true, mode: 0o700, }); await fs.promises.writeFile(outputFilename, content, { encoding: "utf8", mode: 0o600, flag: "wx", }); ``` 5. Implement a documented retention period and automatic deletion mechanism. 6. Provide a command for securely deleting previously retained result files. 7. Add `logs/` to `.gitignore` and packaging exclusions to reduce accidental publication. 8. Document the local persistence behavior, data categories, retention period, and access controls in `SKILL.md` and the README. 9. Consider pseudonymizing stable user identifiers and removing IP-region data before any optional persistence. 10. Add tests confirming that default executions do not create files and that opt-in output files use restrictive permissions. ]]>
