T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:28- Finding
Unscoped Access to Private Memory Files and Session Transcripts
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is openly designed to search prior memories and session logs, but it gives the agent broad access to potentially private history without clear confirmation or source limits.
Review before installing. Use it only if you are comfortable with an agent searching prior memory files or session logs for entertaining recaps. Prefer adding explicit confirmation and source limits before allowing it to inspect transcripts, long-term memory, or broad local history.
SKILL.md:28Unscoped Access to Private Memory Files and Session Transcripts
The trigger phrases are broad enough to activate on ordinary requests like 'random memory' or 'tell me a weird thing from memory,' which can cause the skill to run in contexts where the user did not clearly consent to rummaging through archived memories or logs. In this skill, that ambiguity is more dangerous because activation leads directly to reviewing memory stores and surfacing potentially sensitive historical content.
The skill's core description is to dig through memory logs and retell surprising archived notes, which is functionally a mechanism for extracting and repackaging stored user history. In context, the playful narrative framing makes this more dangerous, not less, because it encourages broad retrieval and dramatic retelling of sensitive content that users may not expect to be resurfaced.
The usage guidance says to use the skill whenever the user wants a random or deep-cut memory or a weird recap instead of a plain summary, but those conditions are subjective and open-ended. Because the skill then searches memory files and session logs, vague routing criteria increase the chance of unintended disclosure from overbroad skill activation.
The skill tells the agent to surface memorable or revealing content from memory sources but does not require warning the user that daily memory files, long-term memory, or session transcripts may be scanned. That missing notice undermines informed consent and can expose users to unexpected retrieval of sensitive prior interactions.
The skill explicitly prefers daily memory files and session transcripts/logs, then instructs the agent to surface unusual or revealing entries as entertainment-style output. This creates a direct privacy risk: historical logs often contain sensitive data, and retelling 'surprising' or 'revealing' content incentivizes disclosure of exactly the material that should be handled conservatively.
No suspicious patterns detected.