T09 · Insecure Skill Coding Practices
- Location
references/architecture.md:57- Finding
Plaintext Retention of Complete Conversation Logs Creates Sensitive Data Exposure
- Content
View full analysis
Vulnerability Details
File Location:
references/architecture.md, lines 57-80
Vulnerability Type: Plaintext sensitive-data retention
Risk Level: MediumEvidence
The following is an English translation of the relevant source excerpt:
text Third layer: Transcript Location: memory/transcripts/YYYY-MM/*.log Responsibilities: - Raw conversation logs - Temporary, context-specific information - Source data for the Topic layer Constraints: - Limit: 500 KB per file, split daily - Retention: keep complete records for 90 days, then compress and archive Data flow: User request / Cron trigger ↓ Write to Transcript (complete log) ↓ Extract key facts and update TopicRelated retention behavior is specified in
references/transcript-spec.md, lines 89-103:text Transcripts older than 90 days: 1. Compress into .gz format 2. Move into memory/transcripts/archive/ 3. Retain an index recordTechnical Analysis
The architecture directs implementations to write complete conversation logs to plaintext
.logfiles. Althoughreferences/transcript-spec.mdlines 11-23 prohibit deliberately storing credentials, financial identifiers, and health records, the design does not define a redaction or classification step before the complete log is written.Conversations can incidentally contain API keys, authentication links, personal data, confidential source code, financial details, or health information. A policy statement alone cannot reliably prevent such content from entering an automatically captured complete transcript.
Archiving old logs with gzip does not provide confidentiality. Gzip is compression rather than encryption, and the design retains archived records indefinitely without specifying deletion, restrictive file permissions, access controls, or encryption at rest. Topic files can also retain extracted personal information, while `references/top ...[truncated 1375 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace “complete log” collection with an explicit data-minimization rule that stores only structured operational events and user-approved summaries.
- Add mandatory redaction before disk writes for passwords, API keys, bearer tokens, cookies, private keys, identity numbers, payment data, authentication URLs, and other configured patterns.
- Require explicit user consent before transcript capture and provide a per-session option to disable recording.
- Default transcript collection to disabled, independently of autoDream and notification settings.
- Create transcript files with restrictive permissions, such as owner-only access, and reject unsafe directories or symbolic links.
- Encrypt retained transcripts and archives using keys managed separately from the workspace. Do not describe gzip as a security control.
- Define a deletion deadline rather than indefinite compressed archival, including deletion from derived indexes and backup systems where feasible.
- Prevent sensitive Topic categories, including health, social, and asset records, from being created without explicit consent and protected storage.
- Add tests using representative secret formats to confirm that sensitive values never reach transcript, Topic, Index, notification, or report files.
