other
- Location
SKILL.md:126- Finding
Unnecessary Persistent Collection of LinkedIn Profile Facts
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 126
Vulnerability Type:other: Unnecessary Persistent Data Collection
Risk Level: MediumComplete Code Snippet:
markdown - Fact/data log in `memory/YYYY-MM-DD.md` for future blog post materialTechnical Analysis
The skill directs the agent to persist a fact/data log in long-term memory after reviewing and correcting LinkedIn experience descriptions. This storage is not necessary to perform the profile audit or apply corrections. Its stated purpose—creating material for future blog posts—is separate from the user-requested profile-correction workflow.
The instruction does not require explicit user consent before storage, define which facts may be retained, exclude sensitive employment information, establish a retention period, or provide a deletion mechanism. Consequently, role clarifications, disputed claims, performance metrics, colleague relationships, and other employment details supplied during the audit could be retained beyond the original session.
This is not classified as T02 Agent Memory Poisoning because the instruction stores profile facts rather than attacker-controlled rules intended to alter future agent behavior. It is instead an unnecessary persistent-data-collection issue.
Attack Path
- The agent extracts experience descriptions from the user's authenticated LinkedIn profile.
- The agent asks the user for clarifications about metrics, deployments, responsibilities, commercial relationships, or contributions.
- The user supplies potentially sensitive employment facts to complete the audit.
- Following the output requirement, the agent writes those facts to
memory/YYYY-MM-DD.md. - The stored information remains available beyond the immediate audit and may later be retrieved or reused for blog content or other sessions without renewed contextual consent.
Impact Assessment
The issue does not grant opera ...[truncated 744 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the requirement to write profile facts to persistent agent memory because it is unrelated to the core audit and correction workflow.
- If retention is offered, make it a separate, explicit opt-in action rather than a default output.
- Display the exact proposed log contents and destination to the user before writing anything.
- Apply data minimization by excluding names, confidential metrics, disputed claims, partner details, and other information unnecessary for the user's approved purpose.
- Separate any user-approved notes from general long-term agent memory and restrict their use to the stated purpose.
- Define a retention period and provide a clear mechanism to inspect, edit, export, and delete stored records.
- Require renewed consent before reusing retained information for blog posts or any purpose outside the LinkedIn audit.
