T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:193- Finding
Unnecessary Access to Persistent Agent Memory and Cross-Project State
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This lottery prediction skill is mostly about its stated task, but it asks the agent to read and modify persistent Claude memory files and use web search without clear user control.
Review before installing. The main risk is not malware; it is that the skill tells the agent to keep lottery prediction history in a hard-coded Claude memory location, update a memory index, and search the web for prior results. Use it only if you are comfortable with that persistence, and prefer changing it to a skill-owned local data file with explicit approval before any read, write, or web lookup.
SKILL.md:193Unnecessary Access to Persistent Agent Memory and Cross-Project State
The manifest description is entirely in Chinese and presents the skill as operating in that language, with no indication that users may choose another language or locale. Under the policy for natural-language violations, a skill should not implicitly force a specific language unless it offers opt-in or clearly documents a justified regional constraint.
The manifest frames the skill as a local lottery-number predictor, but the body adds persistent local file writes and retrospective result reconciliation. This expands the skill's effective capabilities beyond what users or reviewers would reasonably expect, creating a transparency and trust problem and enabling unintended storage of user activity.
The skill describes persistent file writes and web lookups without a clear upfront warning or consent flow. Even if the stored/query data seems low sensitivity, undisclosed persistence and external access can violate user expectations and expose activity history or derived queries without informed consent.
The skill documentation introduces WebSearch for lottery results even though the manifest only describes local prediction based on user-provided dates. Undisclosed outbound queries change the privacy and execution model, and could surprise users by transmitting contextual data externally.
The manifest describes a skill that takes a user-provided lottery draw date, computes Bazi, and generates recommended numbers. In practice, the code also loads historical Excel data, trains multiple machine-learning models, and fits an AR process before prediction, making the skill materially dependent on local dataset ingestion and model training rather than only date-based computation.
The embedded main program hard-codes a specific local filesystem path, revealing developer environment details and creating undisclosed local file access behavior. While not directly exploitable for code execution, hard-coded local paths can leak sensitive host information, cause unintended file reads, and normalize hidden dependencies that are inconsistent with the declared skill behavior.
Automatically updating a separate MEMORY.md index is not necessary for generating lottery predictions and increases the skill's write surface. Extra undocumented writes can create unwanted persistence, make behavior harder to audit, and normalize broader filesystem modification than the stated purpose requires.
This is a natural-language policy concern because the file presents its purpose and operational descriptions exclusively in a single language. There is no indication that Chinese is optional, user-selected, or required for a region-specific use case.
No suspicious patterns detected.