T05 · Unauthorized Access and Privilege Escalation
- Location
research_lead_agent.md:131- Finding
Reference agent prompts mandate unnecessary access to private integrations
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The active skill is mainly a web research helper, but it bundles persistent permission settings and reference prompts that create review-worthy privacy and authority concerns.
Review before installing. Use it only in a constrained project, remove or narrow artifact/.claude/settings.local.json if you do not want broad Edit/Bash permissions, and do not reuse the bundled reference prompts with Slack, Gmail, Drive, Calendar, Asana, or similar integrations unless the user explicitly asks for that private data scope. Avoid putting secrets, confidential business data, internal URLs, or personal medical details into research prompts unless you accept the network and privacy exposure.
research_lead_agent.md:131Reference agent prompts mandate unnecessary access to private integrations
Bundled project settings contain permission-related configuration; activation evidence distinguishes conditional grants from modes ignored on this surface.
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
### Testing Changes
1. Edit skill files
2. Test with: `deep-research <test query>`
3. Iterate based on results
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
### Testing Changes
1. Edit skill files
2. Test with: `deep-research <test query>`
3. Iterate based on results
The skill explicitly instructs the agent to use any additional internal read-only tools 'once or twice' even when they are not relevant to the user's request. That creates unnecessary access to private workspace data and violates data minimization, increasing the chance of unauthorized disclosure of Slack, Asana, Drive, or profile information unrelated to the task.
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
ls .claude/skills/
cat ~/.claude/skills/my-skill/SKILL.md
## 测试 Skill
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# Personal
rm -rf ~/.claude/skills/my-skill
# Project
rm -rf .claude/skills/my-skill
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# Personal
rm -rf ~/.claude/skills/my-skill
# Project
rm -rf .claude/skills/my-skill
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.claude/skills/my-skill
rm -rf .claude/skills/my-skill git commit -m "Remove unused Skill"
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
# View frontmatter
cat .claude/skills/my-skill/SKILL.md | head -n 15
# Check for common issues
# - Missing opening or closing ---
The skill instructs users to submit arbitrary research queries to web-enabled agents without warning that prompts and embedded data may be sent to external services through web_search, web_fetch, or browser tooling. This creates a real privacy and data-handling risk if users include proprietary, personal, or regulated information in queries.
The file includes a medical example prompt about depression treatment but provides no caution that outputs are informational only and should not be used for diagnosis or urgent care. In a web-research skill, this increases the chance users submit sensitive health information or rely on generated summaries for medical decisions.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
- Receives tasks from lead agent
- Uses web tools (web_search, web_fetch, Playwright MCP)
- Reports findings in dense format
- Limited to 20 tool calls
3. **Citations Agent** (`.claude/skills/citations.md`)
- Adds citations to completed reports
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
## 实现的功能
### ✅ 三个核心 Agent Skills
1. **Research Lead Agent** (`.claude/skills/deep-research.md`)
- 查询分析和分类(3 种类型)
This markdown file includes a natural-language locale constraint: '主要针对英语查询优化' ('primarily optimized for English queries'). Under the policy, forcing or preferring a specific language without user opt-in can be a language/locale policy violation, and the file does not present this as an optional user choice or a clearly justified regional requirement.
The title and entire report are written in Chinese, and there is no indication that language selection is optional or that the file is intended only for a Chinese-speaking or region-specific context. The policy calls for flagging language or locale constraints when they are imposed without user opt-in or clear justification.
The README documents automatic use of web_search, web_fetch, and Playwright for dynamic pages, but does not clearly warn users that their queries and possibly surrounding context may be transmitted to external services or remote websites. In a research skill that can automatically browse and fetch pages, lack of disclosure and consent increases privacy and data-handling risk, especially if users submit sensitive prompts.
The README describes web_search, web_fetch, and Playwright-based browsing but does not warn users that their prompts, search queries, and fetched page interactions may be transmitted to external services and third-party websites. This can lead to inadvertent disclosure of sensitive user data if users submit confidential research topics, credentials, internal URLs, or proprietary content.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
### Skill Files
Skills are automatically loaded from `.claude/skills/`:
- `deep-research.md`: Main research coordination
- `research-subagent.md`: Subagent research logic
- `citations.md`: Citation addition
The instructions tell the agent to access integrations and even identify the user or inspect tasks/profile data without any user-facing disclosure or opt-in. This can lead to silent collection and use of personal or organizational data that the user did not realize would be touched during a research task.
The skill mandates use of additional internal tools whenever available, regardless of whether the user requested or needs them. A mandatory-use rule defeats least-privilege behavior and can cause the agent to over-collect sensitive internal data simply because the tools exist.
The skill broadly instructs the agent to access internal communications, tasks, profiles, and documents, including identifying the user, instead of limiting collection to narrowly scoped data. This broad authority materially raises privacy and confidentiality risk, especially in enterprise contexts where integrated systems contain sensitive employee, customer, and business information.
The report gives extensive treatment guidance, medication options, and severity-based recommendations before presenting any crisis or emergency safety guidance. In a mental-health context, a reader in acute distress could rely on the document for self-management and miss the need for urgent help when experiencing suicidal thoughts, psychosis, or inability to stay safe.
The skill explicitly instructs the agent to ALWAYS use internal tools such as Google Drive, Gmail, and Calendar whenever they are available and potentially relevant. That creates a privacy and data-minimization risk because it can cause unnecessary access to personal or non-public data without requiring explicit user consent for the specific task, narrowing scope, or warning about sensitive data handling.
This markdown file presents nearly all instructional content in Chinese, which constitutes a locale/language constraint in natural-language guidance. The document does not offer the user an explicit language choice or explain that the locale is intentionally region-specific, so it fits the policy-violation criteria for forced language without opt-in.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
Skills 存储为包含 `SKILL.md` 文件的目录。
### 个人 Skills
个人 Skills 在您的所有项目中都可用。将它们存储在 `~/.claude/skills/` 中: