T09 · Insecure Skill Coding Practices
- Location
SKILL.md:55- Finding
Automatic Upload of Agent Session Attribution Metadata
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 55–63
Vulnerability Type: Unapproved transmission of local session metadata
Risk Level: MediumVulnerable Code
bash grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null || cargo-ai workspaceManagement session upsert \ --session-id "${SESSION_ID:-$(date +%s)}" \ --title "build-tam-list" \ --summary "[gtm-skills: build-tam-list] Session started from the build-tam-list standalone skill."Technical Analysis
During setup, the Skill checks a local Claude plugin registry and, if the Cargo GTM plugin is not detected, invokes Cargo's remote workspace management functionality to create or update a session record.
This attribution operation is not required to perform the user-requested TAM search. It occurs before the core search command and has no explicit user-consent gate. When the
SESSION_IDenvironment variable exists, its value is transmitted as the remote session identifier; otherwise, a timestamp-derived identifier is used. The static documentation identifies this operation as attribution intended to tell the Cargo team which standalone Skill initiated a workspace.The relevant trust boundary is crossed when locally sourced Agent session metadata is sent to the remote Cargo workspace for product attribution. The code does not minimize a preexisting
SESSION_IDinto a purpose-specific random value or require informed opt-in before transmission.Attack Path
- A user invokes the standalone
build-tam-listSkill and follows its setup instructions. - The local file
~/.claude/plugins/installed_plugins.jsondoes not contain the string"cargo@gtm", or the file does not exist. - The shell
||branch executes automatically. - If present, the local
SESSION_IDenvironment variable is inserted into the command; otherwise, the current timestamp is used. cargo-ai workspaceManagement session upsertsends the identifier, fixed tit ...[truncated 823 chars]
- A user invokes the standalone
- Remediation
View remediation
Remediation Suggestions
- Remove the attribution upsert from the default setup path because it is not necessary for the TAM-list operation.
- If attribution is retained, disclose the exact recipient, fields, and purpose, and require explicit informed opt-in before executing the command.
- Do not reuse the ambient
SESSION_ID. Generate a random, purpose-specific attribution identifier that cannot be correlated with unrelated Agent activity. - Provide a documented telemetry-free setup path and ensure declining attribution does not prevent the core Skill from functioning.
- Minimize retained metadata and document its retention, deletion, and access controls.
- Keep attribution separate from authentication and core search operations so users and Agents can reliably omit it.
