T05 · Unauthorized Access and Privilege Escalation
- Location
memory-transfer.js:50- Finding
Workspace Path Traversal Permits Access Outside Authorized Agent Directories
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real memory-transfer tool, but its filesystem scope and promised safety checks are not reliable enough for automatic installation.
Install only if you are comfortable reviewing commands manually and limiting source and target agent IDs to known safe workspaces. Use dry-run explicitly, avoid clone mode for memories that may contain user data or secrets, and treat share-mode filtering as incomplete until path validation and enforced confirmation are added.
memory-transfer.js:50Workspace Path Traversal Permits Access Outside Authorized Agent Directories
memory-transfer.js:306Untrusted Content Can Be Persisted in Target-Agent Memory
memory-transfer.js:148Documented Confirmation and Dry-Run Safeguards Are Not Enforced
memory-transfer.js:438Positional Argument Parser Misclassifies the Source Agent as a File Filter
The share-mode transformation rules are internally contradictory: one section says first-person pronouns remain first-person, while later examples convert "I/my" into either source-agent references or second-person forms like "you/your." In a memory-transfer skill, this ambiguity can cause identity confusion, incorrect attribution of statements, and accidental reassignment of sensitive or authoritative context to the wrong agent.
Clone mode is documented as preserving all content verbatim, including user names, preferences, contact details, and other personal information, but the documentation does not prominently warn about the privacy and data-governance consequences of copying that data between agents. In this context, the skill is explicitly designed to replicate persistent memory, so unclear privacy guidance materially raises the chance of unauthorized propagation of sensitive user data.
The safety section claims dry-run by default and explicit confirmation before execution, but earlier command examples include direct transfer commands and mode flags that imply immediate execution. This mismatch can mislead operators into assuming a non-destructive preview when the tool may actually perform a real memory copy, increasing the risk of unintended data disclosure or overwrite.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Safety Features
1. **Dry-run by default** - Preview before executing
2. **Explicit confirmation** - Never auto-execute without approval
3. **Backup option** - Can create backup before overwriting
4. **Mode clarification** - Always ask to confirm share vs clone mode
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Safety Features
1. **Dry-run by default** - Preview before executing
2. **Explicit confirmation** - Never auto-execute without approval
3. **Backup option** - Can create backup before overwriting
4. **Mode clarification** - Always ask to confirm share vs clone mode
The privacy filter relies on a narrow set of hard-coded Chinese and simple English-style regexes, creating a false sense of sanitization in share mode. Sensitive user information expressed in other languages, formats, or phrasings will pass through unredacted, so operators may incorrectly assume that shared memory is safe when it is not.
Clone mode writes source memory verbatim into another agent workspace with no mandatory confirmation, warning, or policy gate on the normal non-interactive path. Because memory files may contain sensitive user data, secrets, or prior prompt context, this enables easy cross-agent propagation of private information and increases the blast radius of any sensitive data already present in one workspace.
The help text says share mode leaves 'I, my, me' as first-person so the target agent adopts the knowledge as its own. However, transformForTarget replaces 'I', 'me', 'my', and related contractions with the source agent's name or possessive form, explicitly converting first-person source experience into third-person narration.
The documentation example states 'I work as helper' becomes 'I work as Agent Skill Master'. In code, the pattern /\bI work as\b/ is replaced with ' works as', so the result would be third-person with a conjugated verb, not the documented first-person phrasing.
No suspicious patterns detected.