T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:381- Finding
Overbroad Workspace Inspection May Expose Sensitive Agent Configuration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 381-389; related sensitive-file definition at line 274
Vulnerability Type: Overbroad access to workspace documents
Risk Level: MediumComplete Relevant Snippet
English translation of the relevant source text:
markdown 1. Read trigger state: First read memory/redundancy-check-state.json and determine whether the three-day interval has elapsed. 2. Read the contents of all Markdown files. 3. Execute each item in the nine-item checklist. 3. Pyramid compliance: a. Extract a dynamic keyword fingerprint by scanning every SKILL.md. b. Match the fingerprint against MEMORY.md. c. Scan AGENTS.md for operational or technical content. d. Scan MEMORY.md for mandatory rules or security boundaries. e. Check whether MEMORY.md violates the skill self-containment principle.The file classification table also states:
markdown TOOLS.md: Local configuration notes, including device ports and the storage locations of cookies and API keys.Technical Analysis
The audit procedure instructs the Agent to read every Markdown file in the workspace. This scope is broader than necessary for checking the memory architecture and does not define exclusions for sensitive files.
The same skill explicitly identifies
TOOLS.mdas a location that may contain device information, cookie locations, and API-key locations. Other automatically injected files, such asUSER.md,MEMORY.md, andAGENTS.md, may contain private user details, long-term state, or privileged behavioral configuration. Reading every Markdown file therefore violates least-privilege and data-minimization principles.There is no confirmed instruction to transmit the inspected information externally. The primary exposure is to the Agent context, model-provider processing, conversation logs, tracing systems, or any downstream component that receives the generated report.
...[truncated 1229 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the instruction to read all Markdown files with an explicit allowlist, such as
AGENTS.md,MEMORY.md,HEARTBEAT.md, and selectedSKILL.mdfiles. - Exclude
TOOLS.md,USER.md, credential documentation, private logs, and unrelated project documents by default. - Require explicit user approval before opening any file classified as sensitive.
- Inspect headings, anchors, hashes, or metadata before reading complete file contents.
- Redact secret values, cookie material, tokens, user identifiers, hostnames, and local paths from reports.
- Add maximum file-count and file-size limits to prevent accidental ingestion of an entire workspace.
- State that the generated report must identify affected files and rule categories without reproducing sensitive values.
- Run the scan with read-only access and restrict it to the intended workspace root.
- Replace the instruction to read all Markdown files with an explicit allowlist, such as
