T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/fact_check.py:46- Finding
Unnecessarily Broad Access to Persistent Agent Memory
- Content
View full analysis
Vulnerability Details
File Location:
scripts/fact_check.py:46-54, 414-419
Vulnerability Type: Excessive access to persistent Agent state
Risk Level: MediumVulnerable Code
python def load_memory_logs() -> str: """Load all memory/*.md files into a single string.""" if not MEMORY_DIR.exists(): return "" return "\n\n".join( f"### {f.name}\n{f.read_text()}" for f in sorted(MEMORY_DIR.glob("*.md")) )The collection occurs unconditionally during every fact-check:
python # Load sources findings_text = load_findings() changelog_text = load_changelog() memory_text = load_memory_logs() score_files = load_score_files() status_data = fetch_status_api() git_log_text = load_git_log()Technical Analysis
The implementation reads every Markdown file in the workspace-wide
memory/directory and combines the full contents into one string. This occurs for every draft, even when the draft contains no date or numeric claims that require memory-based verification.Persistent Agent memory can contain unrelated conversation history, decisions, identifiers, operational details, or sensitive information. A fact-checking task ordinarily needs access only to explicitly selected evidence or records relevant to the claims being checked. Reading all memory files violates least-privilege and data-minimization principles.
The audited implementation does not transmit the loaded memory to an external service. However, it systematically places unrelated persistent state into the process's accessible data set. Matching snippets may also influence report evidence. This expands the exposure scope if the process, its output destination, or a future modification is compromised.
Attack Path
- A user invokes the Skill to check a Markdown draft.
run_fact_check()callsload_memory_logs()without requiring consent, an opt-in ...[truncated 1093 chars]
- Remediation
View remediation
Remediation Suggestions
- Disable memory access by default and require an explicit option such as
--include-memory. - Accept specific evidence file paths rather than scanning the entire memory directory.
- Load memory only after extraction confirms that a claim type genuinely requires it.
- Restrict date-related searches to memory files corresponding to the claimed date or an explicitly bounded date range.
- Resolve and validate every selected path against an approved evidence root before reading it.
- Search files incrementally and retain only minimal matching excerpts instead of aggregating full contents.
- Clearly disclose memory access in the Skill documentation and obtain user approval before accessing persistent state.
- Add tests proving that memory files are not read unless the user explicitly enables that source.
- Disable memory access by default and require an explicit option such as
