T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:36- Finding
Overbroad Recursive Inspection of Potentially Sensitive Agent State
- Content
View full analysis
/dev/null ``` ``` ### Technical Analysis The skill instructs the agent to inspect workspace memory, task queues, runtime logs, channel logs, other skills, and core agent documentation. The example commands recursively search entire directory trees and return surrounding context for matches including `auth` and `token`. This collection strategy is broader than necessary to diagnose a specific failure. Files and surrounding lines unrelated to the current task may contain credentials, private conversation content, authentication diagnostics, internal configuration, or data belonging to other tasks. The safety rule against logging secrets does not prevent these commands from reading secrets or returning them into the active agent context. The skill does not define task-level scoping, file allowlists, secret redaction, access approval, or isolation between projects. It therefore weakens least-privilege boundaries at the application level. It does not independently grant new operating-system privileges; exposure is limited to files already readable by the invoking agent. ### Attack Pa ...[truncated 1328 chars]- Remediation
View remediation
