T05 · Unauthorized Access and Privilege Escalation
- Location
batch-screening.md:42- Finding
Overbroad Search of Historical Conversations and Local Attachment Directories
- Content
View full analysis
Vulnerability Details
File Location:
batch-screening.md, lines 42-45
Vulnerability Type:T05: Unauthorized Access and Privilege Escalation
Risk Level: MediumVulnerable Instructions
text 1. Use conversation search or local notes to recover the position name, job-description filename, and candidate list from the previous screening. 2. Search local cache directories for historical attachments: - ~/Downloads/ or the conversation tool's attachment cache directory - Temporary directories commonly used by the user, according to the current agent environmentThe excerpt above is an English translation of the original instructions at the specified location.
Technical Analysis
The Skill directs the agent to search historical conversations, local notes, the user's general Downloads directory, attachment caches, and commonly used temporary directories when reconstructing an earlier screening batch.
These locations are broader than the files explicitly provided or authorized for the current task. They may contain unrelated resumes, job descriptions, personal documents, or files belonging to other sessions. Searching them by default violates least-privilege and purpose-limitation principles.
The risk is amplified because resumes contain personal data, including names, contact details, education history, employment history, and potentially other sensitive information. Filename or keyword filtering does not establish authorization to access or process a file.
Attack Path
- An attacker or ordinary user asks the Skill to re-evaluate a previous candidate batch.
- The Skill attempts to reconstruct the batch through conversation search or local notes.
- It searches broad filesystem locations such as
~/Downloads/, attachment caches, and temporary directories. - The search discovers files that were not explicitly supplied or authorized for the current request.
- Unrelated resumes or job descriptions may be extracted, indexe ...[truncated 747 chars]
- Remediation
View remediation
Remediation Suggestions
- Require the user to identify or re-upload the exact historical files before processing.
- Restrict automatic searches to a dedicated Skill workspace containing only files authorized for the current task.
- Do not search general-purpose locations such as
~/Downloads/, local notes, or global attachment caches. - If historical recovery is necessary, present candidate file paths to the user and obtain explicit confirmation before opening them.
- Maintain a per-session file allowlist and reject files outside it.
- Separate each screening batch into a uniquely named temporary directory with restrictive permissions.
- Record the source and authorization status of every processed file.
- Apply retention controls and securely remove temporary extracted resume text after the task is complete.
