T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:584- Finding
Proactive Calendar Access Without Explicit User Consent
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 584–586
Vulnerability Type: Unauthorized cross-skill access to private calendar data
Risk Level: MediumComplete Code Snippet:
markdown **With Calendar skills:** - Check if user has "Valentine's Day" event - Offer proactive: "I see Valentine's is coming up..."Technical Analysis
The skill instructs the agent to inspect the user's calendar proactively. Calendar access is not necessary for the skill's declared purpose of responding to gift-recommendation requests. The instruction does not require explicit, informed consent before invoking a calendar integration, nor does it define a narrowly scoped query or prohibit access to unrelated event details.
This violates least-privilege principles by encouraging access to a separate source of potentially sensitive personal information beyond what is required to recommend gifts. The resulting proactive statement may also reveal that private calendar data was inspected without the user requesting that action.
Attack Path
- The user activates the Gift Genius skill for a gift-related request.
- The agent follows the multi-skill integration instructions.
- The agent invokes an available calendar tool without first requesting explicit permission.
- The calendar integration searches for a Valentine's Day event and may process event metadata returned by the tool.
- The agent uses the result to initiate an unsolicited prompt such as, “I see Valentine's is coming up.”
- If the calendar tool is broadly scoped, unrelated event information may also become accessible within the agent's execution context.
Impact Assessment
The instruction could cause unauthorized access to private calendar information, including event existence and potentially associated metadata such as dates, attendees, locations, descriptions, or relationship-related context, depending on the calendar tool's permissions ...[truncated 363 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to inspect calendar data proactively.
- Require explicit, informed user consent before invoking any calendar integration.
- Explain what information will be queried and why before requesting permission.
- Limit calendar queries to the narrowest possible scope, such as checking only a user-specified date or event.
- Do not retrieve event descriptions, attendees, locations, or unrelated events unless the user explicitly requests them.
- Handle denial or unavailable calendar access by continuing with ordinary gift recommendations rather than degrading functionality.
- Replace the affected section with consent-based guidance, for example:
markdown **With Calendar skills:** - Only access calendar data when the user explicitly asks for calendar-aware assistance. - Obtain confirmation before invoking the calendar tool. - Query only the date or event explicitly identified by the user.
