T09 · Insecure Skill Coding Practices
- Location
SKILL.md:17- Finding
Plaintext Storage of Sensitive Relationship Data with Unenforceable Access Controls
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:17-25, 89-90, 107, 139, 187-188
Vulnerability Type: Plaintext sensitive-data storage and insufficient access control
Risk Level: MediumComplete Vulnerable Snippets
markdown All emotional data is stored in `data/memo.json`. Create this file on first use with the following structure: ```json { "couple": { "person_a": "", "person_b": "" }, "entries": [], "patterns": [] }text ```markdown 2. Ask for the two people's nicknames or names: "What should I call you both?" 3. Create `data/memo.json` with the couple's names and empty entries/patterns arraysmarkdown 6. **Close warmly** — "I've kept this safe 💛 Thank you for trusting me with it."markdown 1. Read all entries from `data/memo.json`markdown - **Deletion consent:** Deleting another person's entry requires mutual agreement. One person cannot erase the other's recorded feelings. - **Privacy:** If one person asks "what did they say about me?", do not reveal specific entries. Instead: "They've shared some feelings. It might be a good conversation to have together 💛"Technical Analysis
The Skill instructs the Agent to collect and persist names, emotional events, relationship conflicts, triggers, underlying needs, and intensity ratings in a single JSON file. It does not require encryption at rest, restrictive file permissions, authenticated participant identities, participant-specific authorization, integrity protection, consent records, retention limits, or secure deletion.
Both participants' data is placed in the same shared file, and timeline reviews require reading every entry. The stated privacy and mutual-deletion rules are conversational policies rather than enforceable controls. Because the Agent has no documented mechanism for verifying who is speaking, a participant or other workspace user may impersonate another person or bypass the policy by directly accessing the file.
The ...[truncated 1582 chars]
- Remediation
View remediation
Remediation Suggestions
- Obtain explicit, informed consent from every represented participant before persisting personal information.
- Minimize collection by avoiding names and unnecessary free-text details; support pseudonyms and local-only ephemeral sessions.
- Encrypt records at rest using a vetted authenticated-encryption mechanism, with keys stored separately from the data.
- Create files with restrictive permissions and verify that the storage directory is inaccessible to unrelated users and processes.
- Separate each participant's private records and enforce authenticated, participant-specific authorization for reading, updating, exporting, and deleting data.
- Do not rely on conversational claims for identity or mutual consent. Use a verifiable approval workflow for shared disclosure and deletion.
- Add integrity protection, validated schema updates, atomic writes, and protected backups to prevent undetected tampering or corruption.
- Define retention periods and provide authenticated export, revocation, and secure-deletion controls.
- Redact sensitive information from logs, backups, diagnostics, and error messages.
- Replace the unsupported “kept this safe” statement with an accurate disclosure of storage location, protections, access scope, and residual risks.
- Consider storing only consented summaries or pattern identifiers rather than complete descriptions of intimate events.
