T09 · Insecure Skill Coding Practices
- Location
SKILL.md:35- Finding
Automatic Persistence of Sensitive Personal Information Without Adequate Data Controls
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:35-50;references/ORCHESTRATOR.md:67-71;references/CONTEXT-TEMPLATES/健康日志.md:3-22;references/CONTEXT-TEMPLATES/关系图谱.md:3-14;references/CONTEXT-TEMPLATES/财务快照.md:3-26;references/DEPARTMENTS/心理急救箱.md:69-79
Vulnerability Type: Plaintext persistence and uncontrolled duplication of sensitive personal data
Risk Level: MediumRelevant Code Snippet — translated faithfully into English from
SKILL.md:35-50:markdown ## Initialization Process On first use, create the YOU-INC/ directory structure in the user's workspace: 1. Read references/ORCHESTRATOR.md and copy it to YOU-INC/ORCHESTRATOR.md 2. Read all files under references/DEPARTMENTS/ and copy them to YOU-INC/DEPARTMENTS/ 3. Read all files under references/PROTOCOLS/ and copy them to YOU-INC/PROTOCOLS/ 4. Read all files under references/CONTEXT-TEMPLATES/ and copy them to YOU-INC/CONTEXT/ If the directory already exists, skip initialization and enter routing mode directly. ## Core Workflow During every conversation: 1. Intent determination — read YOU-INC/ORCHESTRATOR.md 2. Persona loading — read the corresponding department file 3. Context reading — read the department's private data in YOU-INC/CONTEXT/ 4. Response — respond using the selected persona 5. Memory update — write valuable information back to YOU-INC/CONTEXT/ and memory/ logsRelevant Code Snippet — translated faithfully into English from
references/ORCHESTRATOR.md:67-71:markdown ## Memory Update Rules - After every conversation, write valuable information into the corresponding department's CONTEXT/ file. - Cross-department information must be synchronized, such as health data that affects work arrangements. - For sensitive information such as passwords and financial details, record only a summary rather than the original text.Sensitive fields collected by the templates include:
...[truncated 2892 chars]
- Remediation
View remediation
Remediation Suggestions
- Disable persistent storage by default and require explicit user opt-in before creating or updating context records.
- Show the exact fields and proposed content before each sensitive write.
- Provide field-level controls so users can persist task preferences without storing health, financial, relationship, or mental-health information.
- Prohibit storage of passwords, authentication tokens, recovery codes, payment-card data, and other credentials, including summaries.
- Remove automatic cross-department synchronization. Copy information only when the user explicitly authorizes the destination and purpose.
- Define the exact
memory/destination and prevent writes outside a dedicated, approved directory. - Apply restrictive filesystem permissions and encryption at rest where supported.
- Establish configurable retention periods, automatic expiration, record inspection, export, correction, and secure deletion.
- Minimize records to the least amount of information required for the requested function.
- Warn users against committing the context directory to source control or synchronizing it through untrusted services.
