T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:213- Finding
Overbroad Automatic Access to Work Memory and Conversation History
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:144-147, 158-163, 213-220;references/ALGORITHM.md:14-19, 27-38;references/CONFIG_FULL.md:102-105
Vulnerability Type: Overbroad access to sensitive Agent memory and conversation data
Risk Level: MediumVulnerable Code Snippets
SKILL.md:144-147:markdown 1. **Never auto-install** — All generated Skills require explicit user confirmation 2. **Never delete existing Skills** — Only suggests archiving; you decide 3. **Read-only on work memory** — SkillForge reads your logs but never modifies them 4. **Privacy-first** — Reports contain pattern summaries, never raw quotes from your work logsSKILL.md:158-163:markdown | `scout.lookback_days` | 14 | How far back to scan daily logs | | `scout.similarity_threshold` | 0.65 | How similar two actions must be to cluster together | | `scout.min_cluster_size` | 3 | Minimum occurrences to count as a "pattern" | | `smith.merge_threshold` | 0.70 | When to merge into existing Skill vs. create new | | `sensei.zombie_threshold_days` | 30 | Days of zero usage before flagging as zombie | | `general.realtime_detection` | true | Detect patterns during live conversations |SKILL.md:213-220:markdown SkillForge works best with WorkBuddy's daily log system: - **Required**: Daily log files at `{workspace}/.workbuddy/memory/YYYY-MM-DD.md` - **Optional**: Long-term memory at `{workspace}/.workbuddy/memory/MEMORY.md` **Don't have daily logs yet?** No problem — SkillForge can also analyze your current conversation history. The more data it has, the better the pattern detection. Daily logs just give it a longer memory. **First-time setup**: Just start using SkillForge. It will create its working directory (`{workspace}/.workbuddy/skillforge/`) automatically on first run.references/ALGORITHM.md:14-19:markdown | Data Source | Path | Purpose | |--------|------|------| ...[truncated 3360 chars]- Remediation
View remediation
Remediation Suggestions
- Set
general.auto_scan_enabledandgeneral.realtime_detectiontofalseby default. - Require explicit user authorization before every scan and clearly enumerate the sources, paths, and date range to be accessed.
- Obtain separate opt-in consent for daily logs, long-term memory, conversation history, and installed Skill definitions.
- Default to the narrowest source necessary and provide file-, directory-, topic-, and time-range allowlists.
- Exclude conversation history and long-term memory unless the user explicitly enables them for the current operation.
- Detect and redact credentials, tokens, private keys, personal data, and other secrets before fingerprint extraction or report generation.
- Define retention periods and provide controls to inspect and delete fingerprints, reports, drafts, and health records.
- Store only minimized derived metadata and avoid retaining source excerpts or reversible summaries.
- Display a pre-scan preview and a post-scan record identifying which sources were read and which artifacts were created.
- Enforce workspace boundaries and reject symlinks or paths that resolve outside user-approved directories.
- Set
