Agent Config Directory Access
- Category
- Agent Snooping
- Confidence
- 94% confidence
- Finding
The skill instructs the agent to search the user's ~/.claude/plugins directory, which accesses agent configuration/plugin installation data outside the target project. Even though the stated purpose is plugin discovery, reading from a user-specific config area can expose sensitive local environment details and violates the principle of limiting skills to project-scoped resources. In this context, the danger is increased because the command explicitly enumerates files in a private agent directory rather than asking the user for the path or using a constrained integration API.
- Content
data. Discover it:
bash GRAPH_QUERY=$(find ~/.claude/plugins -name "graph_query.py" -path "*/gauntlet/*" 2>/dev/null | head -1)If gauntlet is not installed: Fall back to static
