T09 · Insecure Skill Coding Practices
- Location
skill.md:117- Finding
Unsanitized User-Controlled Values in File Paths and Shell Command
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This interview-coaching skill is not malicious, but it automatically stores detailed local records of users' interview answers and uses unsafe user-controlled filenames.
Review this skill before installing if you may discuss confidential interview questions, employer code, personal history, or proprietary designs. It should be changed to ask before saving, store summaries by default, validate profile names/domains, avoid shell interpolation, and provide a clear way to delete saved profiles and sessions.
skill.md:117Unsanitized User-Controlled Values in File Paths and Shell Command
The skill automatically saves complete session logs with exact answers, evaluations, timestamps, and improvement plans, but provides no clear up-front warning or consent flow. Because users may paste proprietary code, employer-specific interview questions, or personal details into answers, automatic transcript retention materially increases confidentiality and privacy risk.
Persistent profile storage is a real security-relevant capability because it writes user-linked data to ~/.claude/ai-interview/ for future reuse. In context, this is not inherently malicious, but it is more access than an interview coach strictly needs and becomes risky without consent, minimization, and isolation.
| System Design | Staff Engineer | Architecture, scalability, trade-offs |
| Algorithms/DS | Senior SWE | Problem solving, complexity, optimization |
### Step 1: Load or Create User Profile
User ability profiles are stored in: `~/.claude/ai-interview/`
The skill declares that user ability profiles will be stored on disk under ~/.claude/ai-interview/ but does not clearly warn users in the skill description that their data will be persisted. This creates a privacy and transparency failure: users may disclose personal identifiers or performance data without realizing it will be retained across sessions.
The profile design encourages long-term accumulation of user performance history and topic-level abilities without minimization, expiry, or sensitivity checks. Over time, this builds a behavioral dossier that exceeds what is necessary for a basic interview practice interaction and can reveal learning weaknesses or other personal attributes.
The skill instructs the agent to persist full interview notebooks containing exact user answers, detailed feedback, scores, and timestamps to disk. For an interview-coaching skill, this creates unnecessary retention of potentially sensitive user-provided content and expands the blast radius if local files are later read by other tools, skills, or users on the same system.
The requirement to store and later reproduce users' exact answers in persistent logs creates a data disclosure risk beyond simple scoring or coaching. Exact free-form answers can contain secrets, personal data, copyrighted material, or sensitive work information, and preserving them verbatim makes accidental exposure more damaging.
The session-log persistence capability is real and materially expands the skill's authority by creating durable records of conversations on disk. In an interview coach, that context makes the finding more dangerous because users are likely to share substantial free-form technical content, yet the skill offers no justification strong enough to require automatic archival of full sessions.
**2. Save interview session notebook** for future review:
Create a detailed session log at: `~/.claude/ai-interview/sessions/{username}_{domain}_{YYYYMMDD}_{HHMMSS}.md`
Session notebook format:
The skill includes shell-style directory creation instructions (mkdir -p sessions) even though its stated purpose is interview coaching. This introduces filesystem side effects and nudges the agent toward command-like behavior unrelated to answering interview questions, which can become risky in environments where tool execution is available.
No suspicious patterns detected.