T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:82- Finding
Unauthenticated Public Exposure of Sensitive Long-Term Memory Services
- Content
View full analysis
ngrok http 39300 ``` ```bash curl -i "MCP_URL_MCP" ``` The data returned by the exposed service may include highly sensitive activity: ```markdown - `events[]` — Raw activity events (browser, clipboard, audio, etc.) ``` The skill also explicitly permits arbitrary HTTPS reverse proxies: ```markdown | **Any HTTPS proxy** | `https://your-domain.com` | As long as it forwards to 39300 | ``` ### Technical Analysis The skill instructs users to expose the PiecesOS MCP service running on local port `39300` through ngrok or another public HTTPS proxy. It does not require or describe any substantive access-control mechanism such as: - Tunnel-level authentication - MCP bearer-token authorization - Mutual TLS - Source IP restrictions - Identity-aware proxy enforcement - Per-tool authorization - Read-only access controls The documented `mcp-session-id` is session state rather than an authorization credential. The initialization procedure allows a client to submit an arbitrary initial session identifier and receive a server-assigned identifier. Consequently, possession or discovery of the tunnel URL may be sufficient to initiate a session. This risk is particularly significant because the service can return long-term-memory content and raw events involving browser, clipboard, and audio activity. It also exposes a memory-creation tool, meaning unauthorized access may affect both confidentiality and integrity. ### ...[truncated 1495 chars]- Remediation
View remediation
