T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:100- Finding
Overbroad Access to Persistent Memory and User Profile Files
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 100–104 and 151–156
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: MediumVulnerable Code
markdown ### 4. Memory/Context Files (if using ai-persona-os) **Locations:** - `MEMORY.md` — Permanent facts - `memory/[today].md` — Session notes - `USER.md` — User preferencesThe mandatory data-gathering workflow subsequently directs the Agent to inspect these sources:
markdown Check for these files in order: 1. todo.md (to-do list from ai-meeting-notes) 2. meeting-notes/ folder (recent meeting notes) 3. MEMORY.md (if using ai-persona-os) 4. memory/[today].md (session notes) 5. Calendar integration (if available)Technical Analysis
A daily briefing legitimately requires task, meeting, and calendar information. However, the Skill also instructs the Agent to read permanent memory, session notes, and the general user-profile file. These sources may contain personal facts, historical conversation context, preferences, or other sensitive information unrelated to the requested briefing.
The instructions do not define field-level restrictions, sensitivity filtering, purpose limitations, or an explicit consent step before these persistent files are accessed. Consequently, the workflow violates the principle of least privilege: it permits access to broader persistent context than is necessarily required to summarize the user's current schedule and tasks.
This issue does not grant new operating-system permissions and no external exfiltration mechanism was found. The risk arises when the host Agent already has workspace-reading capabilities and follows the Skill's broad collection instructions.
Attack Path
- The Skill is installed in an Agent that can read files in the user's workspace.
- The workspace contains
MEMORY.md,memory/[today].md, orUSER.mdwith persistent personal or s ...[truncated 1029 chars]
- Remediation
View remediation
Remediation Suggestions
- Make persistent-memory access disabled by default and require explicit user opt-in before reading
MEMORY.md,memory/, orUSER.md. - Use task-specific sources such as
todo.md, recent meeting notes, and the calendar as the default briefing inputs. - Allow users to select individual memory files or approved fields rather than authorizing an unrestricted scan.
- Define an allowlist of briefing-relevant data categories, such as working hours, scheduling preferences, and explicitly marked reminders.
- Exclude sensitive categories by default, including credentials, financial information, health information, private relationship details, and unrelated historical conversations.
- Add a relevance and sensitivity review before memory-derived information is reproduced in a briefing.
- Clearly identify which sources were used and provide a setting that permanently disables persistent-memory integration.
- Limit file reads to the minimum necessary portions and avoid copying complete memory-file contents into model context.
- Make persistent-memory access disabled by default and require explicit user opt-in before reading
