T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:105- Finding
Unnecessary Workspace Memory Access and Context Disclosure
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 105–111
Vulnerability Type: Excessive access to persistent workspace information
Risk Level: MediumVulnerable Code
markdown ## Workspace context injection Before running, check if the user's workspace memory contains project context: - Read `memory.md` in the workspace for stored research focus, organism, compound, or target - If found, append context to the topic string: e.g. `"BACE1 inhibitors [project context: NSCLC, BBB penetration focus]"`Technical Analysis
The skill instructs the agent to read persistent workspace memory and automatically append information from it to the research topic. Running a multi-agent scientific investigation does not inherently require unrestricted access to persistent workspace memory.
This behavior violates least-privilege principles because it expands the skill's data access beyond the topic explicitly supplied by the user. The appended information becomes part of the input passed to
scienceclaw-watchand may consequently be processed by multiple agents or external model services used by that executable.The instruction does not require explicit user consent, define an allowlist of permissible fields, limit the amount of information extracted, or require the resulting enriched topic to be shown to the user before execution.
Attack Path
- A user invokes the skill with an ordinary scientific research topic.
- The skill searches the workspace for
memory.md. - It reads stored project context, which may include information unrelated to the immediate request.
- It appends selected workspace information to the topic string.
- The enriched topic is passed to
bin/scienceclaw-watch. - The additional information may be exposed to every participating agent and any downstream model provider or service used by the executable.
Impact Assessment
The issue can disclose persistent ...[truncated 497 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not read
memory.mdby default. - Ask for explicit, informed user consent before accessing persistent workspace information.
- Allow the user to select the exact file and fields that may be used.
- Apply strict data minimization, such as extracting only an explicitly approved organism, target, or compound name.
- Display the complete enriched topic and require confirmation before invoking the executable.
- Prevent secrets, credentials, personal data, and unrelated project details from being appended.
- Document whether the underlying executable sends prompts to external services and identify the recipients.
- Avoid saving injected workspace context in output artifacts unless the user explicitly requests it.
- Do not read
