T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:34- Finding
Default persistent storage and shared-data access exceed least-privilege requirements
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This summarizer is not malicious, but it automatically keeps local memory and updates shared contact/project notes, so it needs review before installation.
Install only if you want a stateful local summarizer that can remember sources, deadlines, templates, audience preferences, contacts, and project context. For confidential transcripts, contracts, reports, or personal data, prefer disabling storage where possible and reviewing proposed writes to shared contacts or project files.
SKILL.md:34Default persistent storage and shared-data access exceed least-privilege requirements
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**People go to the shared inventory `~/Clawic/data/contacts/contacts.md`**, not here: the recipient of a brief is the same person `clients` or `crm` already knows. One row per person, keyed by lowercase email → handle → `<kebab-name>` — read the file and update that row in place, never append a second one. What is summarizer-specific (their length ceiling, their jargon tolerance, what they always ask for) stays in `## Audiences` in `memory.md`, referencing them by key only.
**No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, and above all not in the source the user pastes in. Transcripts, logs, tickets, and `.env` snippets carry live secrets more often than any other input in this catalog: strip the value and leave the pointer before writing anything to disk — `env:STRIPE_API_KEY`, `keychain:vpn`, `1password:Work/DB/prod`, `file:~/.ssh/id_ed25519` — and say in one line that you did it. If data sits at an old location (`~/summarizer/` or `~/clawic/summarizer/`), move it to `~/Clawic/data/summarizer/`, and say in one line that you moved it and from where.
A summary is a lossy compression with a contract: everything it says is in the source, and everything the reader needs to act is in the summary. Both halves fail silently, so decide the target length before writing and name what you cut. Work from defaults immediately: never open with questions about audience, length, or format — infer from the request, state the assumption in the output header, and correct on feedback. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals: locale, language) → the Configuration table default.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**People go to the shared inventory `~/Clawic/data/contacts/contacts.md`**, not here: the recipient of a brief is the same person `clients` or `crm` already knows. One row per person, keyed by lowercase email → handle → `<kebab-name>` — read the file and update that row in place, never append a second one. What is summarizer-specific (their length ceiling, their jargon tolerance, what they always ask for) stays in `## Audiences` in `memory.md`, referencing them by key only.
**No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, and above all not in the source the user pastes in. Transcripts, logs, tickets, and `.env` snippets carry live secrets more often than any other input in this catalog: strip the value and leave the pointer before writing anything to disk — `env:STRIPE_API_KEY`, `keychain:vpn`, `1password:Work/DB/prod`, `file:~/.ssh/id_ed25519` — and say in one line that you did it. If data sits at an old location (`~/summarizer/` or `~/clawic/summarizer/`), move it to `~/Clawic/data/summarizer/`, and say in one line that you moved it and from where.
A summary is a lossy compression with a contract: everything it says is in the source, and everything the reader needs to act is in the summary. Both halves fail silently, so decide the target length before writing and name what you cut. Work from defaults immediately: never open with questions about audience, length, or format — infer from the request, state the assumption in the output header, and correct on feedback. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals: locale, language) → the Configuration table default.
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
| MD&A / commentary | Management narrative | The explanations given for the numbers, attributed as management's |
- **Adjusted figures are attributed, always.** "Adjusted EBITDA" is a company-defined metric; the summary says whose definition it is and, when the source states it, what was adjusted out.
- **Non-recurring items that recur** every quarter are recurring; if the source shows three consecutive quarters of "one-off" charges, the summary can note the count without judging it.
- **Segment redefinition breaks comparability.** When segments were re-cut, prior-period comparisons in the summary carry a note.
- Forward-looking statements keep their modal: "expects", "targets", "guides to" — never "will".
This instruction mandates writing summary outputs and updating memory files after summarization, creating undisclosed side effects beyond the requested task. Because it can write multiple files automatically, it raises the risk of unauthorized workspace modification, unintended data retention, and leakage of sensitive report contents into long-lived storage.
Updating a shared contacts database from meeting transcripts is outside the core function of summarization and causes the agent to persist personal data derived from potentially sensitive conversations. Because diarization and transcript identity mapping are acknowledged as unreliable in the same skill, this can also introduce inaccurate or misattributed contact records into a shared system.
The skill instructs the agent to perform persistent writes to multiple files outside the requested summary output, including memory, glossary, contacts, project, and summary stores. This expands the skill from summarization into cross-file state mutation, creating a clear risk of unintended data retention, privacy leakage, and corruption of shared knowledge stores from unverified meeting content.
This file materially expands the Summarizer skill into recurring digest production, despite the manifest explicitly excluding recurring external feeds and directing those to a separate digest skill. Scope drift is dangerous because it can cause the agent to apply the wrong trust boundaries, memory behavior, and workflow to ongoing streams, increasing the chance of unauthorized persistence, missed safeguards, or processing sources under a less appropriate policy set.
The instruction to read person-specific audience memory and contacts files before writing for a named person encourages use of stored personal preferences and contact metadata without any privacy notice, consent check, or data-minimization boundary. This can expose unnecessary personal data to the skill and normalize hidden profile-based processing beyond the immediate summarization request.
The instruction to consult audience memory and contacts files before drafting for a named person causes the skill to ingest person-specific preferences and channels from shared storage. In the context of a summarizer, this is more dangerous because it is unrelated to core summarization and broadens data access to personal metadata that may not be necessary for the task.
These lines instruct the agent to add or update named recipients' contact records, preferences, and reusable templates in persistent files, but provide no warning about privacy, retention, or consent. Persisting personal data and inferred preferences from interactions can create unauthorized profiling and long-term data exposure if those shared files are later accessed by other tasks or users.
The file directs the agent to maintain and update external contact and audience-profile files after completing a summarization task. That extends the skill's behavior from summarization into persistent data collection and modification, creating unnecessary privacy, integrity, and scope-expansion risk if the agent stores personal information without explicit user consent or validation.
The skill explicitly instructs storing recipient profiles, preferences, and contact details in shared memory files beyond the current task. Persistent shared storage of person-specific data increases the chance of cross-task leakage, unauthorized reuse, and inaccurate or stale profile data influencing future outputs.
The skill instructs the agent to persist outputs and update multiple project-memory artifacts outside the core act of summarization, including release files, memory indexes, templates, glossary entries, and project tracking files. This creates unintended side effects on local state and can let a simple summarization request silently modify or poison future workflows, especially because no explicit user confirmation or scope check is required.
The instructions go beyond summarization by directing updates to due-item records and project tracking artifacts, which can alter operational planning data and create task entries the user did not request. In skill context, this is more dangerous because users invoking a summarizer would not reasonably expect it to mutate project-management state, making hidden persistence and workflow contamination more likely.
The markdown explicitly directs the agent to write summaries and update several local files without any warning, consent step, or indication that local data will be modified. This is dangerous because it violates user expectations for a read/transform task, increases the chance of silent local data modification, and enables persistence of potentially incorrect or attacker-influenced content into future summaries and release workflows.
Maintaining recurring-report history and user-specific metric definitions introduces cross-session state that is broader than a generic summarizer's core function. This can silently accumulate sensitive business context and influence later outputs in ways the user may not expect or be able to audit easily.
The file instructs the agent to read and update persistent local files as part of normal operation, but it does not warn the user that local memory and glossary data may be modified. Hidden file writes are risky because they can alter user data, create privacy issues, and establish durable state without informed consent.
The instruction expands the skill from pure summarization into persistent state management by requiring updates to memory, glossary, and stored summary files. That creates unintended write side effects, increases data retention, and can modify user workspace contents without an explicit user request or consent flow.
The file broadens the skill from summarization into maintaining recurring-job memory, template lookup, and configuration updates. This scope expansion is risky because it introduces persistent state and behavior changes that are not necessary to summarize content, increasing the chance of unintended data retention or unauthorized local modifications.
Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.
| Slide | ~6 lines, ~8 words per line | One claim per slide; the rest goes to speaker notes |
| Social post | Fixed character count | Write to the count, not to a length band |
| Voice / audio | No visual structure at all | Prose, short sentences, numbers rounded and spoken, no symbols |
| Anything else | Assume markdown, no truncation | Use the ladder default |
## Markers and Formatting
Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.
1. **Cut branches first** (SKILL.md Rule 2) until the point count fits `target ÷ 25`.
2. **Then cut the connective tissue**: "it is worth noting that", "in order to", "the fact that". This is the only genuinely free compression and it typically recovers 10-15% of a first draft.
3. **Then cut adjectives and adverbs**, which carry almost no claim.
4. **Never cut**: negations, hedges, quantifiers, units, attributions, dates. If the count cannot be met without cutting one of these, the count is wrong for this content — say so and give the shortest honest version.
5. **Count before delivering.** "Under 100 words" delivered at 140 is a failed instruction, and it is the most common one.
## Templates
The instructions explicitly tell the skill to persist user-derived templates, style guides, and preferences into local files and config state. For a summarization skill, this creates unnecessary statefulness and local data modification, which can retain sensitive user content or organizational conventions beyond the immediate task without clear consent or bounds.
The documentation directs the agent to write template and style files locally and update configuration without any warning, confirmation, or disclosure to the user. Silent persistence is dangerous because users may provide confidential text assuming it is transient, while the skill stores it for future reuse.
The skill instructs the agent to perform persistent writes to multiple user data stores after summarizing an agreement, including deadlines, sources, summaries, glossary entries, contacts, and project notes. That expands the skill from summarization into state mutation without clear user consent, creating a risk of unintended data retention, privacy leakage, and corruption of trusted records from potentially sensitive contract contents.
The skill directs modification of shared contact and project files, which are broader organizational records not necessary for summarization. Because contract text may contain sensitive identities, engagement details, and inferred relationships, automatic propagation into shared files can leak information across contexts and poison data used by other skills or future tasks.
Detected: suspicious.exposed_secret_literal