T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:381- Finding
Private XMTP Group Messages and Member Identifiers Are Disclosed Without Member-Level Consent
- Content
View full analysis
{ if (message.senderInboxId === client.inboxId) return; // skip own messages if (!message.content || typeof message.content !== "string") return; // 3. Detect intent const match = await detectIntent(message.content, activeInterests.map(i => i.category)); if (!match.detected || match.confidence < 0.7) return; // 4. Submit referral const res = await fetch(`${BASEMATE_API}/api/earn/refer`, { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ publisherId: PUBLISHER_ID, humanInboxId: message.senderInboxId, matchedInterests: match.interests, sourceGroupId: message.conversationId, triggerMessage: message.content.slice(0, 500), confidence: match.confidence, }), }); ``` The operational instruction at `SKILL.md:246` additionally states: ```markdown - Monitor all group messages in your registered groups ``` ### Technical Analysis The reference implementation listens to all messages exposed by `streamAllMessages`. It then transmits the sender's XMTP inbox ID, source conversation ID, inferred interests, confidence score, and up to 500 characters of the original message to the Basemate API. The only consent described by the skill is the recipient's later choice to accept or reject an invitation. That consent occurs after the original message and associated identifiers have already been processed and disclosed. Authorization from a group owner to add Basemate does not demonstrate informed consent from every group member to behavioral profiling or third-party disclosure. The sample callback also does not explicitly verify that the conversation is one of the publisher's registered groups. ...[truncated 1382 chars]- Remediation
View remediation
