T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:77- Finding
Workspace Memory Disclosure Through External Processing and Default Publication
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly aligned with scientific research, but it can automatically mix private workspace memory into externally processed and posted results without clear user approval.
Review this skill before installing. Use it only in workspaces where memory.md does not contain confidential, unpublished, personal, or proprietary research context, and prefer dry-run unless you intentionally want an Infinite post. Verify the ScienceClaw installation path and avoid passing untrusted topic text through a shell command.
SKILL.md:77Workspace Memory Disclosure Through External Processing and Default Publication
SKILL.md:28Shell Command Injection Through Verbatim Topic Interpolation
SKILL.md:22Execution of Unverified Code From a Mutable Installation Path
The 'When to use' section describes triggers such as 'Investigate a scientific topic' and 'Run a deep scientific analysis' across very broad domains, but it does not define clear exclusions or negative examples. This creates ambiguity about when this specific skill should activate versus other research or analysis skills.
The skill instructs the agent to read workspace memory and append that context into the investigation topic sent to an external toolchain, and results may then be posted to Infinite. This creates a direct natural-language exfiltration path for potentially sensitive project details, research plans, organisms, compounds, or other internal context without clear user approval at the time of disclosure.
No suspicious patterns detected.