T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:31- Finding
Overbroad Collection and Persistence of Sensitive Agent and System Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a legitimate reporting purpose, but it tells the agent to gather broad private work, memory, session, and system data and persist/export it without clear user approval or redaction controls.
Review carefully before installing. Use it only for explicitly requested reports, restrict it to selected projects and date ranges, avoid session transcripts and long-term memory unless necessary, redact secrets and personal data, preview the report before saving or sharing, and treat generated HTML/PDF files as sensitive.
SKILL.md:31Overbroad Collection and Persistence of Sensitive Agent and System Data
report-generator.js:13Stored HTML and Script Injection Through Unescaped Report Fields
The skill is explicitly designed to generate manager-facing reports by collecting session transcripts, memory files, git history, container status, cron history, and workspace file changes, yet it provides no privacy boundaries or consent requirements. This creates a clear risk of exposing credentials, private notes, proprietary code details, operational metadata, or unrelated user activity in a report intended for onward sharing.
The trigger phrases include common workplace language like "report to boss," "work summary," and "daily report," which can easily match ordinary user requests and invoke the skill unexpectedly. Because this skill gathers and exports sensitive local data, accidental invocation materially increases the chance of over-collection and unintended disclosure.
These instructions tell the agent to aggregate data from multiple sensitive local sources and transform it into a consolidated boss-facing report. Aggregation increases sensitivity because dispersed operational, personal, and historical data become a single easy-to-share disclosure artifact, potentially revealing far more than the user intended.
The skill instructs persistent storage in memory files and onward delivery as HTML/PDF attachments without any sensitivity classification, retention limits, or sharing controls. Persisting and exporting these reports can compound exposure by leaving sensitive summaries in long-term storage and creating portable files that are easy to redistribute beyond the original context.
The generated document sets <html lang="en">, which forces an English locale in the output regardless of the user's language or report content. This is a natural-language policy concern because the file does not offer a language choice or explain why English is required.
No suspicious patterns detected.