T05 · Unauthorized Access and Privilege Escalation
- Location
AGENTS.md:7- Finding
Automatic Access to User Profile and Persistent Agent Memory
- Content
View full analysis
Vulnerability Details
File Location:
AGENTS.md, lines 7-10
Vulnerability Type: Excessive access to persistent user and session data
Risk Level: MediumEvidence
md - **每次会话启动时**: 1. 读取 SOUL.md — 确认 COO 身份与当前职责 2. 读取 USER.md — 了解 CEO/董事会的最新战略方向 3. 读取 memory/YYYY-MM-DD.md(今日 + 昨日)— 追踪 OKR 进展与待办Technical Analysis
The skill instructs the agent to read
USER.mdand the current and previous daily memory records at the beginning of every session. These reads are mandatory and are not conditioned on whether the requested task requires historical memory, user-profile information, or strategic context.This behavior violates least-privilege and data-minimization principles. The declared skill interface requires only a task description, but the startup process expands the effective input to include persistent user and organizational data. Such data may include prior tasks, strategic plans, operational risks, or other information unrelated to the current request.
The finding does not establish that data is deliberately exfiltrated. However, once the files enter the active model context, their contents can influence outputs and may be included in reports, tool requests, or inter-agent communications.
Attack Path
- A user or another agent activates the COO skill for an ordinary operational task.
- The startup instructions cause the agent to read
USER.md. - The agent also reads the current and previous daily files under
memory/. - Sensitive historical or strategic information enters the active model context even if it is unrelated to the task.
- A crafted task, follow-up prompt, or downstream agent request induces the agent to summarize, quote, or forward information from that context.
- The unrelated persistent information is exposed through the response, an inter-agent message, or an external report.
Impact Assessment
Exploitation could provide access to user-prof ...[truncated 547 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove unconditional startup reads of
USER.mdand daily memory files. - Require an explicit task dependency before accessing persistent records.
- Ask for user confirmation before reading user-profile or historical-memory files containing sensitive information.
- Read only explicitly identified records and only the minimum relevant sections.
- Introduce a sensitivity classification and redact credentials, personal information, confidential strategy, and unrelated historical content before adding records to model context.
- Prevent persistent-memory content from being included in inter-agent or external messages unless the user separately authorizes the disclosure.
- Record the reason, file, requesting task, and destination whenever persistent information is accessed or transmitted.
- Treat content loaded from memory as untrusted data rather than executable instructions.
- Remove unconditional startup reads of
