T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/config_loader.py:21- Finding
Automatic Cross-Workspace Access to Private Agent Memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This memory skill is partly purpose-aligned, but it can automatically read, index, mix, persist, archive, and report broad local memory data without clear enough user control.
Install only if you are comfortable with this skill reading and indexing local WorkBuddy memory across detected workspaces. Before use, set explicit memory_dirs, disable or remove analytics, avoid SOUL.md silent startup hooks, review archive behavior carefully, and keep backups before running !记忆归档 or archive_memory.py --exec.
scripts/config_loader.py:21Automatic Cross-Workspace Access to Private Agent Memory
SKILL.md:554User-Linked Analytics Instructions Without a Defined Consent or Privacy Boundary
scripts/index_memory.py:15Unverified Dependency and Model Retrieval Through a Non-Official Mirror
scripts/archive_memory.py:205Cross-Workspace Archive Filename Collision Causes Memory Contamination and Backup Loss
The skill introduces packaging, archive creation, directory copying, and Desktop output operations that are unrelated to the core memory function advertised to users. These ancillary filesystem behaviors expand the attack surface and can be abused to exfiltrate, duplicate, or persist data in unexpected locations, especially when shell commands are agent-executed.
The skill introduces packaging, archive creation, directory copying, and Desktop output operations that are unrelated to the core memory function advertised to users. These ancillary filesystem behaviors expand the attack surface and can be abused to exfiltrate, duplicate, or persist data in unexpected locations, especially when shell commands are agent-executed.
The skill introduces packaging, archive creation, directory copying, and Desktop output operations that are unrelated to the core memory function advertised to users. These ancillary filesystem behaviors expand the attack surface and can be abused to exfiltrate, duplicate, or persist data in unexpected locations, especially when shell commands are agent-executed.
The skill directs the agent to automatically read prior memory files, recent diaries, and historical conversations, then inject and summarize them in the first response. This is dangerous because it normalizes cross-session data access and disclosure without a fresh request, increasing the likelihood of exposing sensitive personal or business information in a new context.
The skill instructs persistence of conversation content into diaries and long-term memory after important decisions and near conversation end, including automatic file creation and append operations. Persisting user dialogue by default creates substantial privacy risk, can store secrets or regulated data permanently, and may do so without sufficiently specific user consent at the time of capture.
The README’s primary descriptive text is written in Chinese and does not indicate any language choice, opt-in, or locale-specific justification. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The skill instructs use of shell commands, file reads/writes, and environment-dependent paths, but it does not declare any explicit tool scope or permission boundaries. That creates an over-privileged, ambiguous execution model where an agent may access local files and execute shell operations beyond what users reasonably expect from a 'memory enhancement' skill.
The skill name, description, commands, and generated templates are written as Chinese-specific interactions and reference Chinese models and Chinese command phrases. The file does not offer users a language/locale option or state that the skill is intentionally limited to a Chinese-only deployment context.
The skill instructs automatic retrieval of MEMORY.md, recent diaries, and historical conversation topics at conversation start, then surfaces summaries in the first reply. Doing this without a clear privacy warning or opt-in can expose sensitive prior-session data to the user interface or to anyone viewing the current session, even when the user did not request recall.
This duplicate persistence finding is valid for the same reason: the skill normalizes saving conversation-derived content into durable diary and memory files. In a memory tool, context increases—not decreases—the danger because the retained material is likely to include highly sensitive summaries of user work and prior chats.
### ⚠️ 重要规则
- 日记文件不存在时,自动创建(mkdir -p + touch)
- 追加模式,用 `echo` 或 `cat >>` 写入,**永远不要覆盖日记文件**
- MEMORY.md 更新时,只修改相关段落,不要重写整个文件
- **每次压缩后,立即提醒用户:可以随时用 `!找记忆` 搜索这些内容**
This duplicate persistence finding is valid for the same reason: the skill normalizes saving conversation-derived content into durable diary and memory files. In a memory tool, context increases—not decreases—the danger because the retained material is likely to include highly sensitive summaries of user work and prior chats.
### ⚠️ 重要规则
- 日记文件不存在时,自动创建(mkdir -p + touch)
- 追加模式,用 `echo` 或 `cat >>` 写入,**永远不要覆盖日记文件**
- MEMORY.md 更新时,只修改相关段落,不要重写整个文件
- **每次压缩后,立即提醒用户:可以随时用 `!找记忆` 搜索这些内容**
The search workflow retrieves and presents excerpts from long-term memory, diaries, and historical conversations in response to broad recall-style prompts. Without tighter scoping and consent, this can surface sensitive excerpts that the user did not intend to re-expose in the current session.
The trigger conditions match broad natural-language phrases such as requests to 'help me find' prior discussions, which can cause the skill to retrieve long-term memory and historical conversations without a precise command boundary. In a privacy-sensitive memory tool, overly broad invocation increases the chance of accidental disclosure of prior content.
The skill says generated skills must not auto-inject marketing content unless the user explicitly supplies parameters, yet the parent skill itself contains built-in promotional links and contact details. This contradiction undermines trust and may normalize hidden promotional injection into outputs or derivative skills.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
• 行业降噪规则
📥 本地安装:
mkdir -p ~/.workbuddy/skills/memory-{domain-slug}/
mv memory-{domain-slug}.md ~/.workbuddy/skills/memory-{domain-slug}/SKILL.md
📤 可独立打包为 ZIP,发布到任意 Skill 平台(需注明依赖 memory-booster)。
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
• 行业降噪规则
📥 本地安装:
mkdir -p ~/.workbuddy/skills/memory-{domain-slug}/
mv memory-{domain-slug}.md ~/.workbuddy/skills/memory-{domain-slug}/SKILL.md
📤 可独立打包为 ZIP,发布到任意 Skill 平台(需注明依赖 memory-booster)。
The auto-reminder logic treats phrases such as “确定”, “好的”, “OK”, and “下次再说” as triggers for memory-compression prompts. These are common in everyday conversation and the file does not define context checks to prevent excessive or unintended reminders.
The automatic trigger logic performs silent history access when the user says the agent forgot something, without disclosing that prior chats or local files will be searched. This hidden retrieval creates an expectation gap and can expose historical context that the user did not intend to reopen automatically.
The skill silently triggers memory retrieval whenever the user says things like 'you forgot' or 'I mentioned this before.' Because this can access historical conversations and local memory without an explicit current-session request, it materially raises the chance of unexpected data access and disclosure.
The skill defines automatic telemetry events including identifiers and usage metadata that are not necessary for core memory retrieval and persistence. Collecting and transmitting such data creates an avoidable privacy and data-governance risk, especially because this skill handles potentially sensitive conversation history and local memory contents.
The analytics section specifies automatic reporting of user_id and usage metadata but provides no explicit warning, consent mechanism, or data-handling disclosure. In a skill that processes personal memory and conversation history, silent telemetry materially increases privacy and compliance risk.
The module docstring and all user-facing operational messages are written only in Chinese, indicating the skill is intended to operate in a fixed language/locale. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
print("\n🔄 重建语义索引...")
try:
import subprocess
result = subprocess.run(
[sys.executable, str(Path(__file__).parent / "index_memory.py"), "--force"],
capture_output=True, text=True, timeout=300
)
The module docstring and inline documentation are written exclusively in Chinese, which reflects a language-specific constraint without any indication of user opt-in or locale justification. Under the policy, language restrictions should either offer a choice or be clearly documented as region-specific.
The module docstring says subsequent runs perform incremental updates that index only new files or new content. In practice, build_index either returns early when a collection already exists or deletes the entire collection and rebuilds it when forced; no file hashes or per-file change detection are used despite a hash helper being present.
No suspicious patterns detected.