T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:34- Finding
Automatic Cross-Session Access to Dynamically Indexed User Files
- Content
View full analysis
.md` before proposing a payload shape, a schema, or a format change for work the user tracks as a project. If none of it exists, work from defaults and say nothing about it. ``` ### Technical Analysis The Skill requires the agent to read persistent configuration and memory at the beginning of every session, regardless of whether the current JSON task needs that information. It also treats the mutable `## Boxes` index as an extensible source of additional files to open. Restricting indexed paths to `~/Clawic/data/` limits filesystem scope, but it does not provide least-privilege isolation within that directory. The declared configuration paths include shared project and contact data. Consequently, unrelated historical, project, or personal context can be loaded into the active agent session without a task-specific need or explicit approval. The instruction to read files according to ...[truncated 1404 chars]- Remediation
View remediation
