T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:6826- Finding
Unredacted Agent Conversations and Tool Data Can Be Published to a Git Remote
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed local memory-sync tool, but it can archive raw agent conversations and tool data into a Git-staged vault without built-in redaction.
Install only if you are comfortable with a local tool copying agent conversations, tool outputs, rule files, profile data, project metadata, and skill inventories into an Obsidian vault. Keep the vault private, review generated Sources and review packs before running git sync, leave GIT_PUSH_ENABLED=false unless the remote is private and intended for this data, and avoid scanning conversations that may contain credentials, customer data, private keys, or regulated information.
scripts/main.py:6826Unredacted Agent Conversations and Tool Data Can Be Published to a Git Remote
The declared purpose frames the skill as memory preservation and sync, but the body authorizes broader behavior: scanning conversation histories across products, parsing local SQLite databases, probing local application homes, exporting transcripts, and capturing project state. This mismatch can cause users or orchestrators to approve the skill under a narrower mental model while it performs substantially more invasive data collection than the top-level description suggests.
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
Referenced artifact was not completely inspected
python scripts/main.py sync
No suspicious patterns detected.