T09 · Insecure Skill Coding Practices
- Location
SKILL.md:9- Finding
Automatic External Persistence of Potentially Sensitive Gmail Context Without Explicit Consent or Redaction
- Content
View full analysis
" \ -H "Content-Type: application/json" \ -d '{"text": "Thread w/ vendor: quote sent 7/28, awaiting PO.", "title": "gmail-memory - note"}' ``` ## Quick note ```bash curl -X POST .../agent-note \ -H "Authorization: Bearer " \ -H "Content-Type: application/json" \ -d '{"text": "Thread w/ vendor: quote sent 7/28, awaiting PO.", "tags": ["gmail-memory"]}' ``` ## Recall ```bash curl -X POST .../agent-recall \ -H "Authorization: Bearer " \ -H "Content-Type: application/json" \ -d '{"q": "What's the latest in my thread with the vendor?"}' ``` ## Workflow 1. On new context, first recall: `What's the latest in my thread with the vendor?` 2. Use the answer to personalize the response 3. After the interaction, store the summary via `/agent-remember` ``` ### Technical Analysis The skill instructs the agent to retrieve a BlueColumn API credential from `TOOLS.md` or a platform secret store and use it to send Gmail-thread summaries to an external Supabase-hosted service. The workflow directs the agent to store a summary after the interaction without requiring explicit user approval for that transmission. Email threads can contain personal information, commercial terms, internal communications, access links, credentials, or other confidential material. The instructions provide no requirements for: - Obtaining informed consent before an external write. - Limiting storage to user-selected threads or fields. - Detecting and redacting credentials, tokens, personal data, or confidential con ...[truncated 2264 chars]- Remediation
View remediation
