T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:32- Finding
Excessive Persistent Profiling and Ambient Data Access
- Content
View full analysis
Vulnerability Details
File Locations:
SKILL.md:32-55SKILL.md:79-87contexts.md:3-14contexts.md:23-38contexts.md:59-73templates.md:23-67examples.md:30-42
Vulnerability Type: Excessive persistent collection of sensitive context and implicit access to screenshots and connected work sources
Risk Level: MediumRelevant Code Snippets:
SKILL.md:32-55markdown Store context in `~/copilot/` (or user-configured path):~/copilot/ ├── active # Current focus: project, task, blockers ├── priorities # Key projects, people, deadlines
├── decisions # Append-only log: [DATE] TOPIC: Decision | Why ├── patterns # Learned preferences, shortcuts, style └── projects/ ├── auth-service # Per-project context ├── dashboard # History, decisions, patterns └── ...text | File | When to Read | When to Update | |------|--------------|----------------| | active | Every activation | On context change | | priorities | Morning / weekly | When priorities shift | | decisions | When checking history | After any significant decision | | projects/* | On project switch | After work session | **On EVERY activation:** Read active first. Never ask "what are you working on?" if you can infer it.SKILL.md:79-87markdown | When | Screenshot? | |------|-------------| | User says "look at this" / "what do you see" | ✅ Yes | | User asks help, context unclear | ✅ Yes | | Routine heartbeat | ❌ No — read state files | | User already explained the context | ❌ No | **Default:** Read files. Screenshots only when truly needed.contexts.md:23-38markdown ## Knowledge Work Context **Signals:** Docs, email, calendar, Slack mentions ### Proactive Opportunities - Meeting in 30 min? Prep context from last meeting - Email from key stakeholder? Surface it - Deadline approaching? Remind with ...[truncated 5211 chars]- Remediation
View remediation
Remediation Suggestions
- Require explicit, informed opt-in before enabling persistent memory and separately authorize each data source, including screenshots, terminals, email, calendars, Slack, logs, and infrastructure tools.
- Permit screenshots only after explicit confirmation for the current request. Do not treat unclear context as sufficient authorization.
- Replace “read operations: always OK” with source-specific least-privilege rules and require confirmation before accessing sensitive communications, configuration files, infrastructure inventories, or production data.
- Minimize stored data. Exclude credentials, tokens, terminal secrets, SSH destinations, server inventories, private communications, third-party personal information, and unrelated screen content by default.
- Show users a preview of proposed memory updates and obtain confirmation before persisting sensitive information or behavioral “standing rules.”
- Apply restrictive filesystem permissions to the state directory and files, such as owner-only access, and verify permissions when files are created.
- Encrypt sensitive state at rest using an operating-system-backed credential or key-management facility rather than storing sensitive context as unrestricted plaintext.
- Define configurable retention periods, automatic expiration, selective deletion, export, and a straightforward mechanism to disable all persistence.
- Add redaction and secret-detection controls before storing screenshots, terminal output, configuration content, communications, or logs.
- Record the source and timestamp of each stored fact so users can review provenance and remove stale or incorrectly inferred information.
