Back to skill

Security audit

Copilot

Security checks for vulnerabilities and agentic risk

Overview

The skill is not overtly malicious, but it asks the agent to persist and reuse broad personal, work, screenshot, messaging, calendar, and DevOps context without strong consent, scoping, or retention controls.

Install only if you are comfortable with a copilot keeping local cross-session notes about your projects, people, decisions, work habits, and some operational context. Before using it, configure a private storage path, avoid logging secrets or regulated data, approve screenshots and email/Slack/calendar access explicitly, and periodically review or delete ~/copilot/.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:32
Finding

Excessive Persistent Profiling and Ambient Data Access

Content
View full analysis

Vulnerability Details

File Locations:

  • SKILL.md:32-55
  • SKILL.md:79-87
  • contexts.md:3-14
  • contexts.md:23-38
  • contexts.md:59-73
  • templates.md:23-67
  • examples.md:30-42

Vulnerability Type: Excessive persistent collection of sensitive context and implicit access to screenshots and connected work sources
Risk Level: Medium

Relevant Code Snippets:

SKILL.md:32-55

markdown
Store context in `~/copilot/` (or user-configured path):

~/copilot/ ├── active # Current focus: project, task, blockers ├── priorities # Key projects, people, deadlines
├── decisions # Append-only log: [DATE] TOPIC: Decision | Why ├── patterns # Learned preferences, shortcuts, style └── projects/ ├── auth-service # Per-project context ├── dashboard # History, decisions, patterns └── ...

text

| File | When to Read | When to Update |
|------|--------------|----------------|
| active | Every activation | On context change |
| priorities | Morning / weekly | When priorities shift |
| decisions | When checking history | After any significant decision |
| projects/* | On project switch | After work session |

**On EVERY activation:** Read active first. Never ask "what are you working on?" if you can infer it.

SKILL.md:79-87

markdown
| When | Screenshot? |
|------|-------------|
| User says "look at this" / "what do you see" | ✅ Yes |
| User asks help, context unclear | ✅ Yes |
| Routine heartbeat | ❌ No — read state files |
| User already explained the context | ❌ No |

**Default:** Read files. Screenshots only when truly needed.

contexts.md:23-38

markdown
## Knowledge Work Context

**Signals:** Docs, email, calendar, Slack mentions

### Proactive Opportunities
- Meeting in 30 min? Prep context from last meeting
- Email from key stakeholder? Surface it
- Deadline approaching? Remind with 
...[truncated 5211 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed opt-in before enabling persistent memory and separately authorize each data source, including screenshots, terminals, email, calendars, Slack, logs, and infrastructure tools.
  2. Permit screenshots only after explicit confirmation for the current request. Do not treat unclear context as sufficient authorization.
  3. Replace “read operations: always OK” with source-specific least-privilege rules and require confirmation before accessing sensitive communications, configuration files, infrastructure inventories, or production data.
  4. Minimize stored data. Exclude credentials, tokens, terminal secrets, SSH destinations, server inventories, private communications, third-party personal information, and unrelated screen content by default.
  5. Show users a preview of proposed memory updates and obtain confirmation before persisting sensitive information or behavioral “standing rules.”
  6. Apply restrictive filesystem permissions to the state directory and files, such as owner-only access, and verify permissions when files are created.
  7. Encrypt sensitive state at rest using an operating-system-backed credential or key-management facility rather than storing sensitive context as unrestricted plaintext.
  8. Define configurable retention periods, automatic expiration, selective deletion, export, and a straightforward mechanism to disable all persistence.
  9. Add redaction and secret-detection controls before storing screenshots, terminal output, configuration content, communications, or logs.
  10. Record the source and timestamp of each stored fact so users can review provenance and remove stale or incorrectly inferred information.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction 'Disclaimers before acting — Just do the thing' is especially dangerous in a skill whose examples include screenshots, persistent context, and monitoring private activity. It suppresses transparency at precisely the moments users need notice and consent, making privacy-invasive or high-risk actions more likely to occur without informed approval.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The direction to make interactions feel continuous and avoid re-asking for prior information semantically pushes the agent toward broad memory of earlier user inputs. Even without explicit file instructions on that exact line, this behavioral goal increases pressure to retain more context than necessary and can normalize persistent collection of user data across sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly directs the agent to persist user context across sessions in files under ~/copilot/ without any accompanying user notice, consent flow, or retention/privacy safeguards. This creates a real risk of storing sensitive project details, personal information, or work history in durable natural-language memory that may be accessed later or retained longer than the user expects.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions encourage routine persistence and reuse of cross-session context in multiple state files, but do not define minimization, sensitivity boundaries, or retention limits. In practice this can lead the agent to accumulate broad histories of user activity, decisions, priorities, and patterns, increasing privacy exposure and the blast radius if the files are later read by other tools, users, or processes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The development context is activated by very broad ambient signals like an IDE, terminal, git activity, or code files, all of which are common during normal work. That can cause the skill to infer sensitive state and act proactively without a clear opt-in boundary, increasing the chance of unwanted monitoring, data collection, or intrusive suggestions in routine developer workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The knowledge-work context relies on very broad signals such as docs, email, calendar, and Slack mentions, which can expose highly sensitive business communications and personal workflow data. Because the skill also proposes surfacing stakeholder emails and preparing meeting context, the lack of strict activation constraints raises meaningful privacy and over-collection risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly states that it will remember stakeholders, project status, recurring meetings, and decision patterns in persistent storage, but it does not present a user-facing privacy warning or consent model. This creates a concrete privacy risk because it normalizes retention of potentially confidential organizational information across sessions without clear disclosure, review, or deletion controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The System/DevOps context is triggered by generic terminal, SSH, and config-file activity, which can overlap with normal administrative work involving sensitive environments. In this context, broad activation is more dangerous because logs, hostnames, topology, and operational metadata may be exposed, and proactive behavior around staging or production can influence high-impact workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example normalizes taking a screenshot of the user's workspace and inferring code context without any explicit consent, notice, or boundary-setting. In a copilot skill, that behavior can expose sensitive source code, tokens, customer data, or other on-screen information and conditions the agent to perform privacy-impacting actions silently.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This example encourages the agent to monitor prior work activity, external service changes, and Slack messages, then surface that private context proactively without any user-facing notice. In a persistence-focused copilot, silent cross-tool monitoring increases the risk of surveillance-like behavior, leakage of private communications, and over-collection of workplace data beyond user expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill specifies creation and maintenance of persistent state files containing project, task, and recent activity context, but it does not clearly require explicit user consent or a prominent notice at the point of collection/write. This can lead to unexpected retention of sensitive work context on disk, including project names, blockers, and workflow habits, which creates privacy and confidentiality risk on shared or monitored systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The /log behavior appends user-provided content into an append-only decisions file, but the implementation does not clearly warn that the content will be permanently recorded locally. Users may include sensitive rationale, business decisions, incident details, or secrets in a casual message, resulting in unintended durable storage that is harder to review or remove than transient chat context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to create and maintain persistent files under ~/copilot/ containing sensitive behavioral and personal context such as priorities, named contacts, workflow habits, schedules, and project history. Even without overt exfiltration, this creates a privacy and security risk because the data can accumulate silently across sessions, be retained longer than expected, and become accessible to other local processes, users, backups, or later prompts without explicit user consent or data minimization.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The creative-context signals are somewhat ambiguous, such as long-open files or reference images, and may trigger during ordinary design or writing activity without clear user intent. While typically less sensitive than email or ops contexts, this still risks unnecessary inference about user work patterns and unwanted persistence of preferences or asset information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.