T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/callback.py:137- Finding
Unauthenticated Cross-Session Prompt Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill openly enables high-impact WorkBuddy cross-session message injection, but it lacks hard authorization controls and its script can send callback data to arbitrary endpoints despite loopback-only claims.
Install only if you specifically need WorkBuddy Desktop session-to-session callbacks and are comfortable with one session or automation waking another with its full context. Do not inject untrusted external input, avoid remote or non-loopback --endpoint values, use fixed target-session allowlists where possible, label callback messages as external notifications, require confirmation before sensitive actions, and remove temporary automations after use.
scripts/callback.py:137Unauthenticated Cross-Session Prompt Injection
scripts/callback.py:100Arbitrary Network Endpoint Permitted Despite Loopback-Only Security Claims
The skill explicitly instructs reading local session registry/transcript files and making HTTP requests to local ACP endpoints, but it declares no tool scope or permission boundaries. Because this skill enables cross-session message injection into other agent sessions, the missing explicit restrictions increase the chance that an agent or user invokes sensitive file and network actions without clear guardrails or review.
The documentation explicitly enables injecting arbitrary user messages into another active session and confirms that the target agent will continue with its full prior context. Because loopback requests are exempt from authentication and the feature is framed as a general callback mechanism, this creates a real cross-session integrity and privacy risk: any local process able to reach the endpoint can steer another session, trigger actions, or cause unintended disclosure from that session’s retained context. The absence of strong warnings, consent requirements, or scope restrictions makes misuse substantially more likely.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## 定时调度
- 可靠调度:WorkBuddy 内置 automation(宿主进程调度,独立于 agent 回合)
- 不可靠:nohup / Start-Process 后台进程(随 agent 回合结束被回收)
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## 定时调度
- 可靠调度:WorkBuddy 内置 automation(宿主进程调度,独立于 agent 回合)
- 不可靠:nohup / Start-Process 后台进程(随 agent 回合结束被回收)
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## 定时调度
- 可靠调度:WorkBuddy 内置 automation(宿主进程调度,独立于 agent 回合)
- 不可靠:nohup / Start-Process 后台进程(随 agent 回合结束被回收)
The header comment documents an unauthenticated loopback flow that obtains connectionId and sessionToken from local ACP endpoints and then loads and prompts arbitrary sessions. Even if intended for localhost use, this creates a trust boundary bypass: any local code able to reach the endpoint and discover session metadata may impersonate a client and manipulate agent state without meaningful authentication or user awareness.
The script explicitly injects arbitrary user-controlled text into another live session via session/prompt, causing the target agent to resume with its full prior context and potentially take actions in that session. This is a cross-session state modification primitive with no confirmation, authorization gate, or warning, so a local process, cron job, or another session can silently steer a different agent thread and trigger unintended actions.
This manifest description says the skill enables one session, external process, cron job, or another session to inject messages and wake a target agent, but it does not describe concrete activation boundaries or exclusion conditions. In a manifest file, this broad wording can make it unclear when the skill should be invoked versus when similar automation or messaging tasks should not use it.
The manifest description is written entirely in Chinese and does not indicate that other languages are supported or that the language is a user-selectable preference. This can be a natural-language policy concern if the skill is expected to be usable in multiple locales without forcing a specific language.
The user-facing docstring and CLI help text are written in Chinese only, which imposes a language choice on users without opt-in or explanation. Under the language/locale policy, forcing a specific language without offering a choice or documenting a justified regional constraint is a policy concern.
No suspicious patterns detected.