other
- Location
SKILL.md:14- Finding
Unconditional Ingestion of Potentially Sensitive Third-Party Content
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14–25
Vulnerability Type: Unauthorized Data Ingestion and Privacy Exposure
Risk Level: MediumVulnerable Code
md Push content into Lore using the `ingest` tool whenever you encounter information worth preserving: - **After conversations**: When a user shares meeting notes, interview transcripts, or important documents, ingest them so they're searchable later. - **External content**: When you fetch content from Slack, Notion, GitHub, email, or other systems, ingest the relevant parts into Lore. - **Decisions and context**: When important decisions are made or context is shared that future conversations will need. Always include: - `source_url`: The original URL (Slack permalink, Notion page URL, GitHub issue URL) for citation linking. - `source_name`: A human-readable label like "Slack #product-team" or "GitHub issue #42". - `project`: The project this content belongs to.Technical Analysis
The skill instructs the agent to transfer conversation material and content obtained from external services into the Lore repository whenever the agent considers it worth preserving. This broad trigger does not require explicit user consent for each transfer, confirmation that the user is authorized to copy third-party content, sensitivity classification, secret scanning, personal-data redaction, or destination and retention validation.
The required metadata may compound the disclosure by associating ingested content with internal project names, source-system identities, and direct resource URLs. Although ingestion is the skill's declared function, making it automatic based on subjective agent judgment creates a privacy and data-governance weakness.
Attack Path
- A user provides confidential meeting notes, an interview transcript, or another sensitive document, or permits the agent to retrieve content from Slack, Notion, GitHub, or email.
- The agent determines that the informa ...[truncated 1077 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit, item-specific user confirmation before every ingestion operation.
- Present the exact content, source metadata, destination project, and intended retention behavior before requesting approval.
- Verify that the user is authorized to copy content from the originating system into Lore.
- Apply data-loss-prevention controls before transfer, including secret detection and redaction of credentials, tokens, personal data, and unnecessary confidential details.
- Use source and project allowlists rather than permitting ingestion from arbitrary external systems.
- Minimize metadata by excluding source URLs, project identifiers, and participant information unless required and approved.
- Define repository access controls, retention periods, deletion procedures, and audit logging.
- Replace “whenever you encounter information worth preserving” with a consent-based rule that defaults to no ingestion.
