T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/indexer.py:99- Finding
File Symlinks Can Bypass the Allowed-Root Metadata Boundary
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local file-metadata indexer with disclosed scope and no evidence of exfiltration, deception, or destructive behavior.
Install only if you are comfortable keeping a local searchable catalog of filenames, paths, sizes, and dates from your Documents and Downloads folders. Consider tightening catalog file permissions and avoiding ambiguous use of the broad "where is" trigger.
scripts/indexer.py:99File Symlinks Can Bypass the Allowed-Root Metadata Boundary
scripts/indexer.py:56Metadata Catalog Files Are Created Without Explicit Restrictive Permissions
The skill describes executable commands that read from and write to the local filesystem and store a SQLite database, but it does not declare any explicit tool scope or permissions boundary. In an agent environment, missing scope declarations can let the skill be invoked with broader-than-intended file access, undermining the documented claims about allowed roots and blocked directories if those constraints are not enforced by the platform.
The trigger phrase "where is" is broad and can match many ordinary user requests unrelated to filesystem indexing, increasing the chance that this skill is activated unexpectedly. That can cause unintended enumeration of local files and metadata disclosure, especially because the skill is designed to search across user directories and return paths, dates, and sizes.
No suspicious patterns detected.