T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:41- Finding
Overbroad Workspace Profile Access and External Location Disclosure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Waze-link skill does what it says, but it asks agents to read broad profile files and automatically send location context to an external search service without a clear consent step.
Review this skill before installing if your workspace or agenda contains sensitive location information. It should be safer if limited to explicit user requests, exact approved profile fields, and confirmation before sending city, state, destination, or calendar-location details to Tavily.
SKILL.md:41Overbroad Workspace Profile Access and External Location Disclosure
The activation scope is broad enough to trigger on routine mentions of destinations, routes, or agenda items, which can cause the skill to run without clear user intent. In this skill, that matters because activation can lead to location inference from profile files and possible downstream external lookup for vague destinations, increasing the chance of unnecessary processing of sensitive location data.
The skill directs automatic processing of agenda event locations and, for vague locations, external search based on the user's city, without informing the user or requesting consent. This can expose sensitive calendar and location context to external services and may surprise users who did not explicitly ask for navigation assistance.
No suspicious patterns detected.