T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:70- Finding
Sensitive Session Transcripts Are Included in the Recommended Knowledge-Base Build
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This instruction-only skill is purpose-aligned, but it recommends broad indexing of Claude session transcripts into persistent local knowledge stores and depends on an unpinned external source install.
Install only after auditing or pinning the external Fabrik-Codek source you will run. Before building the knowledge base, review `~/.claude/projects/` for secrets or private conversations, avoid broad transcript ingestion unless you need it, and keep the MCP transport on stdio or localhost-only. Treat the generated `./data/` indexes as sensitive because they may contain derived copies of transcript content.
SKILL.md:70Sensitive Session Transcripts Are Included in the Recommended Knowledge-Base Build
SKILL.md:162Unpinned Installation of External Source and Development Dependencies
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
Configure as an MCP server in your openclaw.json or ~/.claude/settings.json:
{
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
### Session transcript privacy
The `fabrik learn` command reads Claude Code session transcripts, which may contain sensitive data (code, credentials, conversation history). This command is **opt-in** — you must run it manually. It does not run in the background or on a schedule unless you explicitly configure `fabrik learn watch`. Review what's in your `~/.claude/projects/` before indexing.
### Source verification
No suspicious patterns detected.