T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:56- Finding
Mandatory External Publication of Draft Content Without Per-Action Consent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a blog-writing helper, but it requires sending draft content to a fixed Notion database without a fresh user confirmation.
Install only if you want this skill to publish writing to the configured Notion database as part of its normal workflow. Do not use it for private notes, sensitive research, or unfinished drafts unless you first edit the skill to require explicit confirmation before every Notion write and to verify the destination.
SKILL.md:56Mandatory External Publication of Draft Content Without Per-Action Consent
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
### Context Is Key
Providing ChatGPT with clear context is vital. It narrows down the AI's focus to your specific subject, leading to more accurate and useful responses. Contextualized prompts require more details but offer more refined outputs.
### Assuming Identities and Professions
The declared description describes a content-generation and publishing skill focused on producing authentic long-form writing in a specific voice. The supplied code does none of that. Instead, it inspects a local directory of blog example markdown files, reports library status, and can delete the oldest files when limits are exceeded. This is a materially different primary purpose and introduces undeclared file-management/deletion behavior. Therefore, the description does not accurately represent the code.
The skill mandates automatic publication of full draft content to Notion, even before finalization, and does so without requiring explicit user approval at the time of transmission. This creates a real risk of exfiltrating sensitive notes, proprietary research, or unfinished drafts to an external service, especially when users may think they are only asking for local drafting help.
The activation conditions are broad enough that the skill could trigger on many ordinary writing requests such as 'write this in my style' without clearly establishing scope or obtaining consent for downstream actions. In this skill's context, overbroad triggering is more dangerous because activation leads into publication and persistence steps, increasing the chance of unintended data handling.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Voice & Tone
- **Direct and opinionated**: State positions clearly, even contrarian ones
- **Conversational**: Write like speaking to a colleague—accessible without being simplistic
- **First-person when sharing experience**: Use "I" naturally for personal insights
- **Authentic skepticism**: Willing to criticize trends when warranted
No suspicious patterns detected.