T09 · Insecure Skill Coding Practices
- Location
prompts/persona_builder.md:13- Finding
Sensitive source text may be retained despite an explicit no-retention guarantee
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not overtly malicious, but it needs Review because it encourages broad inspection of logged-in personal accounts and private chats, then saves sensitive local profiles with weak retention controls.
Install only if you are comfortable with an agent seeing sensitive social-media history, private chats, screenshots, and derived personal traits. Prefer redacted pasted excerpts over browser access, set narrow platform/date/content limits, avoid third-party private conversations unless everyone consents, and inspect or delete generated `profiles/` files and backups after use. Treat the unpinned `npx` install command as mutable installer guidance.
prompts/persona_builder.md:13Sensitive source text may be retained despite an explicit no-retention guarantee
prompts/evolution.md:28Profile versioning preserves sensitive superseded data and may undermine deletion
README.md:38Unpinned npx installation executes a mutable third-party package
SKILL.md:44Authenticated browser and private-chat collection exceeds least-privilege defaults
The skill permits browser-based access to logged-in personal accounts and describes extracting pages, screenshots, and behavioral features, but it lacks a strong upfront warning about exposure of sensitive data in those sessions. In context, the targeted platforms can reveal private messages, interests, social graphs, and historical content, so insufficient warning materially raises privacy risk.
The prompt authorizes browser-mediated access to the user's logged-in accounts so the agent can navigate personal history. Even with the user logged in, this is a highly intrusive capability that can expose private content beyond the intended scope and normalizes delegated access to sensitive accounts.
The instructions tell the agent to browse logged-in personal accounts and extract private historical content for later reporting. Combining direct access to private account data with local persistence of that content creates a strong risk of over-collection, accidental retention, and exposure of highly sensitive personal material.
The output schema requires saving sensitive excerpts and inferred traits about the user's past behavior, authenticity, social embarrassment, and life changes into structured files. Such profiling is especially risky because it turns intimate historical content into durable, searchable artifacts that could be misused, leaked, or repurposed beyond the user's expectations.
The prompt escalates from light self-reflection to agent-assisted access of authenticated social-media accounts, allowing collection of sensitive personal data far beyond what is needed for the stated purpose. It also normalizes downstream persistence of derived profiles, creating a privacy and surveillance risk if the agent over-collects, mishandles credentials, or stores inferred sensitive traits.
The README instructs users to install via npx clawhub install digital-life without pinning a specific version of the tool being executed. This creates a supply-chain risk because npx may fetch and run the latest published package, so a compromised or malicious update to clawhub could execute arbitrary code on the user's system.
The README promotes browser-driven collection of highly sensitive personal social-platform data, including direct access to logged-in personal pages, but does not present a prominent privacy and sensitivity warning at the point of collection. In this skill context, the data categories are unusually intimate and retrospective, so lack of explicit warning increases the chance users expose more data than they intended.
The README explicitly instructs the agent to gather personal social-media data, pasted chat logs, screenshots, and directly access logged-in personal pages. In the context of a skill designed to analyze intimate digital traces, this materially increases privacy and data-handling risk because the agent may receive broad access to sensitive content unrelated to the immediate task.
The README states that generated Markdown contains complete analysis derived from the user's digital traces, which may preserve sensitive personal details in human-readable files. This creates secondary exposure risk because Markdown summaries are easy to browse, sync, share, or leak, and may retain more identifiable information than necessary.
The README claims '所有分析本地进行,不上传任何服务器' while elsewhere describing browser-driven collection of users' logged-in social-platform pages by an agent. That contradiction can mislead users about where sensitive personal data flows, undermining informed consent and increasing the risk of unintended disclosure to the agent runtime, browser tooling, or remote services.
The trigger list includes broad natural-language phrases such as “前世”, “墓志铭”, and “digital life” that could plausibly appear in ordinary conversation outside the intended skill-invocation context. Although some trigger rules are listed later, the manifest-level description does not provide negative examples or narrow contextual constraints to prevent unintended activation.
The skill claims analysis is local and not uploaded, yet it instructs the agent to collect data from logged-in browser sessions and via web fetching from online services. Even if exfiltration is not explicit, this still expands access to highly sensitive account data and can mislead users into underestimating privacy exposure.
The safety claims 'do not upload' and 'look but don't touch' are undermined by instructions to extract content from live logged-in accounts and to write outputs to disk. This mismatch can cause users to rely on stronger privacy guarantees than the implementation actually provides, increasing the chance of overcollection and accidental retention of sensitive data.
The skill is framed as a reflective 'archaeology' tool, but its workflow explicitly creates persistent user profiles, keeps version history, supports rollback, and manages deletion of those dossiers. That introduces data retention and longitudinal profiling risks beyond what a user would reasonably expect from a lightweight self-reflection utility.
The skill documents writing generated profiles and reports to local files, preserving old versions, and supporting rollback, but it does not present this retention model as a clear privacy warning to the user. Persistent multi-version dossiers increase the harm from local compromise, accidental sharing, or misuse by other tools or users on the same system.
The entire skill file is written as mandatory instructions in Chinese and does not offer any language choice or opt-in for users. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is documented and justified, which is not present here.
The skill content is entirely in Chinese and provides no indication that users may choose another language or that language preference will be detected. This can exclude or confuse users who do not read Chinese, increasing the risk of misunderstanding sensitive self-reflection content and reducing informed user participation.
The skill explicitly instructs collection of highly sensitive chat data from multiple private and public contexts, including exports, pasted conversations, and browser-assisted screenshots, then persists inferred persona traits to profile files. There is no visible requirement for informed consent, data minimization, retention limits, redaction of third-party data, or warning that local files containing sensitive inferences will be created, which creates substantial privacy and secondary-use risk.
The prompt requires at least two contexts of conversation data and directs the system to infer sensitive psychological/persona traits such as trust thresholds, private persona, and social masking, then save them in persistent profile files. This materially increases the risk because it combines intimate communications across contexts into durable behavioral profiling, which can expose the user and third parties to privacy harms, misuse, or unauthorized access if the files are retained or shared.
The prompt explicitly directs the agent to obtain and analyze historical social-media content, including via browser access to personal pages, which is significantly more intrusive than the broad manifest description of 'archaeology tools.' This creates a transparency and informed-consent gap around collection of sensitive personal history and downstream profiling.
The skill collects and stores sensitive personal history and derives emotionally loaded inferences, yet the prompt contains no explicit privacy warning, consent language, retention notice, or explanation of risks. Users may not appreciate that deeply personal archives and inferred traits are being processed and saved.
The skill instructs persistent storage of JSON and Markdown reports containing sensitive excerpts and psychological/behavioral inferences such as 'mask turning point' and 'lost things.' Persisting this kind of intimate profiling without clear disclosure, minimization, retention limits, or consent materially increases privacy and misuse risk.
The skill describes collecting digital footprint data, including browser-assisted account inspection, without an explicit privacy notice, purpose limitation, or handling warning. In this context, users may reveal deeply personal information while not understanding that the agent could inspect authenticated services, making informed consent inadequate and increasing the chance of surprise data exposure.
The prompt authorizes browser-assisted inspection of a user's logged-in accounts and digital footprints for an epitaph/reflection feature, which exceeds what is necessary to generate the core output and increases access to sensitive account data. This broadens the attack surface for over-collection, accidental disclosure, and misuse of session-authenticated information unrelated to the user's stated request.
The skill explicitly persists highly sensitive personal reflection data, inferred life-summary fields, and generated psychological content to local profile/report files, yet the prompt provides no explicit user consent flow, retention limits, or minimization guidance. Even if digital traces are optional, storing this kind of intimate data creates privacy and secondary-use risks if the files are later accessed, synced, or reused without the user's awareness.
No suspicious patterns detected.