T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:127- Finding
Unauthorized Probing of Agent Configuration Files Outside the Declared Workspace
- Content
View full analysis
/dev/null # Check for AI Persona OS ls ~/workspace/SOUL.md ~/workspace/AGENTS.md 2>/dev/null | wc -l ``` ### Technical Analysis The skill instructs the Agent to probe `~/workspace/SOUL.md` and `~/workspace/AGENTS.md` before displaying any menu. These files are outside the skill's declared `~/workspace/leadgen/` operational boundary and may contain unrelated Agent configuration, behavioral rules, or persistent state. This behavior contradicts the explicit scope restriction in `SKILL.md` and the later assertion that the skill does not access files outside `~/workspace/leadgen/` without permission. Although the command only determines whether the files exist and does not read their contents, it still performs unauthorized reconnaissance against unrelated Agent configuration. No SSH-key access or modification was found. The automated SSH warning in the original scan was a keyword false positive. ### Attack Path 1. A user installs or activates the lead-generation skill. 2. The skill mandates that the post-install check run before any menu is shown. 3. The Agent executes `ls` against `~/workspace/SOUL.md` and `~/workspace/AGENTS.md`. 4. The result reveals whether unrelated Agent configuration files exist. 5. The skill can subsequently alter its behavior based on information obtained outside its legitimate workspace. ### Impact Assessment The direct information exposure is limited to file existence and count. The command does not itself read file contents or obtain elevated operating-system privileges. However, it violates least-privilege boundaries and permits cross-skill reconnaissance. In an Agent environment where `SOUL.md` or `AGENTS.md` controls persistent behavior, even existenc ...[truncated 194 chars]- Remediation
View remediation
