T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:8- Finding
Unnecessary Agent Memory Access Violates Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8–12
Vulnerability Type: Excessive tool permissions
Risk Level: Mediumyaml allowed-tools: - read - write - memory_search - memory_getTechnical Analysis
The skill declares access to
memory_searchandmemory_get, although its documented workflow only requires analyzing conversation text supplied in a user message or file. No documented operation requires access to unrelated Agent memory.This configuration violates the principle of least privilege. In a host that exposes declared tools to the skill, these permissions could allow the Agent to search and retrieve persistent information that is unrelated to the transcript being analyzed. Transcript content may be untrusted and could contain prompt-injection instructions intended to induce use of the available memory tools.
The file does not explicitly instruct the Agent to retrieve or disclose memory, so this finding concerns unnecessary authorization and the resulting exposure surface rather than confirmed memory exfiltration. The skill does not declare a memory-writing tool, and therefore this is not classified as Agent Memory Poisoning.
Attack Path
- A host loads the skill and grants the tools declared under
allowed-tools. - A user supplies an untrusted conversation transcript containing instructions designed to influence the Agent's analysis.
- The injected content induces the Agent to call
memory_searchfor terms associated with credentials, private conversations, identities, or prior tasks. - The Agent calls
memory_getto retrieve matching stored records. - Retrieved information is incorporated into the generated conversation report or otherwise exposed in the current session.
This path requires a host that treats the declared tools as authorized and an Agent that follows the untrusted transcript instructions without enforcing a separation between transc ...[truncated 523 chars]
- A host loads the skill and grants the tools declared under
- Remediation
View remediation
Remediation Suggestions
- Remove
memory_searchandmemory_getfromallowed-tools, retaining only tools strictly required by the documented workflow. - Remove
writeas well if reports are only returned to the user and no file-output feature is required. - If memory-backed transcript retrieval is an intended feature, require explicit user consent and selection of the exact memory record before access.
- Restrict searches to a user-approved namespace, conversation identifier, or bounded date range rather than allowing unrestricted memory queries.
- Treat all transcript content as untrusted data and explicitly prohibit following instructions embedded within analyzed transcripts.
- Prevent memory-derived content from being included in reports unless the user has expressly requested that specific content.
- Add tests confirming that ordinary transcript analysis never invokes memory tools and that prompt-injection text inside a transcript cannot trigger memory retrieval.
- Remove
