T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:442- Finding
Unnecessary Access to Persistent Agent Memory
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 442
Vulnerability Type: Excessive access to persistent Agent context
Risk Level: MediumVulnerable instruction translated into English:
text When answering: first use memory_search to search memory, then read the corresponding files and functions in the /root/ultralytics source tree. All example code must come from official built-in functions and must not be invented.Technical Analysis
The Skill mandates a
memory_searchoperation before answering every YOLO or Ultralytics question. Access to historical or persistent Agent memory is not required to answer questions using the local/root/ultralyticssource tree.This instruction violates the principle of least privilege by requesting access to a potentially sensitive information source without defining a relevant query scope, obtaining user authorization, or limiting which retrieved information may influence the response. Persistent memory could contain information from unrelated conversations, including personal details, confidential project context, internal paths, or credentials.
The audited file does not instruct the Agent to transmit retrieved memory to an external service, alter it, or establish persistence. Therefore, the confirmed issue is excessive access rather than memory poisoning or demonstrated data exfiltration.
Attack Path
- A user asks a YOLO or Ultralytics-related question, activating the Skill.
- The final instruction requires the Agent to invoke
memory_searchbefore inspecting the relevant source code. - An insufficiently scoped search retrieves historical context unrelated to the current question.
- Retrieved information affects the answer or is accidentally reproduced in it.
- The current user may consequently receive information originating from another conversation or context.
No additional privilege-escalation step, external transmission channel, o ...[truncated 602 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the mandatory
memory_searchrequirement. - Answer questions by reading only the files and functions under
/root/ultralyticsthat are necessary for the current request. - Use persistent memory only when the user explicitly requests it or when a clearly documented feature requires prior context.
- Require narrowly scoped memory queries and exclude unrelated conversations, credentials, personal data, and secrets from results.
- Ask for user confirmation before incorporating sensitive historical context into a response.
- Apply tenant and conversation isolation to the memory system and redact sensitive values before returning search results.
- Record memory access in an audit log containing the requesting Skill, query scope, purpose, and returned data classification.
- Remove the mandatory
