T09 · Insecure Skill Coding Practices
- Location
SKILL.md:75- Finding
Unconfirmed Automatic Access and Modification of Persistent Customer Memory
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 75–78
Vulnerability Type: Automatic persistent-memory access without explicit user approval
Risk Level: MediumComplete Relevant Skill Instructions:
markdown ## Memory Integration - Before preparing for a visit, retrieve historical interactions from `memory/customers/{customer_name}.md`. - After the visit, remind the user to conduct a visit review using the Sales Review Manager's `review-visit` scenario. - Automatically append the current visit-preparation content to the customer memory file.The excerpt above is an English rendering of the complete source segment at the specified lines.
Technical Analysis
The Skill directs the agent to retrieve historical customer interactions and automatically append generated visit-preparation content to persistent customer memory. It does not require explicit user approval before either operation and does not specify validation or normalization of the customer name used to select the memory file.
This creates two security concerns:
- Historical customer information may be retrieved and incorporated into a response without confirming that the current user is authorized to access it.
- User-controlled or model-generated content may be written into persistent records without review, allowing inaccurate, sensitive, or adversarial content to influence later sessions.
If the implementation directly substitutes a supplied customer name into the documented path, insufficient path validation could also allow unintended file selection. The reviewed package contains no implementation code proving that path traversal is possible, so this aspect remains a conditional risk rather than a confirmed exploit.
Attack Path
- A user supplies a customer name and visit context containing inaccurate, misleading, or adversarial information.
- The Skill uses the customer name to identify a persistent file unde ...[truncated 1209 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit user confirmation before reading customer history and again before writing generated content to persistent memory.
- Display the target customer record and a preview of the proposed changes before committing them.
- Validate customer identifiers against a strict allowlist of expected characters and lengths.
- Resolve and normalize the target path, then verify that it remains within the designated
memory/customers/directory. - Use an authorization check to ensure that the current user may access the selected customer record.
- Store structured, provenance-tagged entries rather than appending unrestricted text. Record the source, timestamp, author, and confidence level.
- Exclude unnecessary personal, confidential, and credential-like information from persistent storage.
- Treat stored customer content as untrusted data when it is retrieved, and never interpret stored text as agent instructions.
- Maintain an audit log and provide rollback or deletion controls for erroneous entries.
- Add tests covering unauthorized record access, malicious customer identifiers, path traversal attempts, instruction-like memory content, and rejected or cancelled writes.
