other
- Location
SKILL.md:19- Finding
Access to Sensitive Agent Memory and Dream Records
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 19–30
Vulnerability Type: Sensitive Agent Memory Access
Risk Level: MediumEvidence
markdown ## Sources Read only the sources authorized for this reading. Typical sources are: - `MEMORY.md`; - recent `memory/YYYY-MM-DD.md` notes; - `memory/.dreams/events.jsonl`; - `memory/.dreams/phase-signals.json`, when relevant. Default to the last 7–14 days. Use up to 30 days only when the user approves or the shorter period is too sparse. Missing files are unavailable. Do not infer their contents. Do not search unrelated folders, messages, email, external services, or third-party records.Technical Analysis
The Skill directs the Agent to read persistent memory and dream-record files. These resources may contain sensitive personal history, relationships, health-related reflections, behavioral patterns, or other private information.
This access is explicitly constrained: the Skill requires user authorization, limits the default period to 7–14 days, prohibits searching unrelated locations, and is documented as read-only. It therefore does not constitute privilege escalation or malicious memory modification. Nevertheless, processing these files creates a confidentiality risk because sensitive source content and derived conclusions may be exposed through the conversational response.
No executable code, remote payload retrieval, external transmission, persistence mechanism, credential collection, or file modification was identified.
Attack Path
- A user invokes the Clairvoyance Skill in a private conversation.
- The user authorizes one or more listed memory or dream-record sources.
- The Agent reads sensitive records from the authorized paths.
- The Agent derives themes or patterns from those records.
- Sensitive details or revealing inferences may appear in the generated response.
- Anyone who can access the active conversation or its retained transcript may consequently ...[truncated 832 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit confirmation of every source path and the exact time range immediately before reading.
- Default to the shortest practical period and require renewed approval before expanding it.
- Present a source-access summary before processing and allow users to exclude individual files.
- Minimize direct quotations and avoid reproducing unnecessary identifying or highly sensitive details.
- Apply output redaction for credentials, authentication tokens, financial information, health details, and third-party personal data.
- Remind users that generated interpretations and retained conversation transcripts may reveal information derived from private records.
- Ensure the Skill can run only in a verified private conversation and fails closed in shared or ambiguous contexts.
- Preserve the existing prohibitions against writes, scripts, external calls, uploads, unrelated searches, and access to another person's data.
