T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:29- Finding
Unscoped Access to Persistent Agent Memory During Claim Verification
- Content
View full analysis
" ``` ``` ### Technical Analysis The skill instructs the agent to consult persistent memory through `MEMORY.md` or the `memory_search` tool when verifying a claim. It does not limit searches to records relevant to the current user, session, or task, and it provides no consent, authorization, redaction, or data-minimization requirements. Persistent agent memory can contain personal information, prior conversation content, credentials, operational details, or information unrelated to the current request. Because the prescribed output format includes an `Evidence` field, retrieved memory content could be reproduced in an answer. The risk depends on the host environment granting this skill access to persistent memory; the file itself does not independently bypass access controls. ### Attack Path 1. The skill activates before the agent returns a consequential or high-confidence answer. 2. A claim is selected for verification. 3. Following lines 58–61, the agent submits that claim to `memory_search`; line 29 additionally directs it to check established memory. 4. An overly broad or adversarially constructed claim causes the search to return unrelated persistent records. 5. Sensitive content from those records is treated as supporting or contradictory evidence. 6. The agent may disclose that content in the skill's required `Evidence` output field. ### Impact Assessment If the host exposes sensitive persistent memory to the skill, the agent may read information beyond the minimum scope required for the current task. Potential impact includes disclosure of prior-session content, personal information ...[truncated 326 chars]- Remediation
View remediation
