T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:96- Finding
Workspace Memory May Be Disclosed to External Services and Public Posts
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly a clear science-posting workflow, but it can automatically mix local workspace memory into content that may be published publicly.
Install only if you are comfortable with a workflow that can post to Infinite by default. Prefer --dry-run first, review the generated content, and do not allow automatic memory.md context reuse unless you have checked that the memory contains nothing private, unpublished, or identifying.
SKILL.md:96Workspace Memory May Be Disclosed to External Services and Public Posts
SKILL.md:26Shell Command Injection Through Verbatim Topic Interpolation
The skill’s default behavior is to publish generated content to an external platform, but the description and usage guidance do not prominently warn that execution will post unless --dry-run is used. This creates a real risk of unintended external disclosure of generated research content, user inputs, or derived context, especially in agent-driven workflows where a user may expect a local draft rather than publication.
The workspace context injection step tells the agent to read memory.md and append stored project context into the topic, but it provides no privacy warning or consent boundary before that context may flow into generated output and be published. This is dangerous because prior workspace notes can contain sensitive research direction, compounds, targets, or organizational context that the user did not intend to disclose in a public post.
This instruction explicitly directs the skill to read workspace memory and append it into the topic, which can propagate prior stored user or project data into LLM prompts, generated summaries, and ultimately public Infinite posts. In this skill’s context, the danger is amplified because the workflow is designed to publish externally by default, turning prompt-context reuse into a concrete data-leak path rather than a purely internal prompt-handling issue.
No suspicious patterns detected.