T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:193- Finding
Unnecessary Access to the Agent Profile
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 193–201
Vulnerability Type: Least-privilege violation through access to unrelated local configuration
Risk Level: MediumRelevant Code:
markdown Local SQLite tracker for job applications synced from Gmail. **Before invoking any tracker command, read `~/.claude/profile.md`:** 1. Check `Integrations > Tracker Backend` — if `tracker_backend` is `notion`, the tracker subcommand is not applicable; use the `application-manager` skill instead. 2. If `tracker_backend` is `sqlite` (or blank, defaulting to sqlite for local use), read `SQLite DB path` from profile.md. Use that value as `--db PATH`. Fall back to `~/.offerplus/applications.db` only if the field is blank.Technical Analysis
The Skill requires the agent to read the entire
~/.claude/profile.mdfile before every tracker command. This file is outside the project and may contain unrelated integration settings, local paths, preferences, or other persistent agent configuration.The tracker only needs a database path and, optionally, a backend identifier. Reading a general-purpose agent profile therefore exceeds the minimum filesystem privileges required to add, update, query, or export records from a local SQLite database.
Although the instructions do not explicitly direct the agent to transmit the profile, making the profile part of the Skill's execution context unnecessarily exposes its contents to the agent and any downstream command-generation process.
Attack Path
- A user asks the agent to perform a tracker operation.
- The Skill instructs the agent to open
~/.claude/profile.md. - The agent reads the whole profile to resolve
tracker_backendand the SQLite path. - Unrelated configuration contained in that profile enters the active execution context.
- That information could be exposed through logging, model context retention, accidental output, or a s ...[truncated 533 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not require automatic access to
~/.claude/profile.md. - Accept the tracker database path through an explicit
--dbargument or a dedicated environment variable. - Use
~/.offerplus/applications.dbwhen the user does not provide a path. - If backend discovery is essential, ask for explicit user consent before reading external configuration.
- Retrieve only the required fields through a narrowly scoped configuration interface rather than reading a general-purpose profile.
- Validate user-supplied database paths and clearly display the selected path before performing write operations.
- Do not require automatic access to
