T09 · Insecure Skill Coding Practices
- Location
assets/extension-template/index.ts:92- Finding
Cross-Session Telemetry Disclosure and Misattribution
- Content
View full analysis
(); const recentOutputs: Usage[] = []; ``` The lookup function supports session-specific retrieval, but falls back to the latest globally observed output: ```ts function latestUsage(sessionKey?: string): Usage | undefined { if (sessionKey && recentBySession.has(sessionKey)) return recentBySession.get(sessionKey); return recentOutputs.at(-1); } ``` Subagent aggregation also processes outputs from unrelated sessions based primarily on temporal proximity: ```ts function aggregateSubagents(root?: Usage, cacheMs = 120000): { input: number; output: number } | null { if (!root) return null; const cutoff = Date.now() - cacheMs; let input = 0; let output = 0; for (const u of recentOutputs) { if (u === root || u.ts < cutoff) continue; if (Math.abs(root.ts - u.ts) > cacheMs) continue; if (u.sessionKey && root.sessionKey && u.sessionKey === root.sessionKey) continue; input += u.input ?? 0; output += u.output ?? 0; } return input || output ? { input, output } : null; } ``` The `llm_output` hook populates these shared caches: ```ts api.on("llm_output", async (event: any, ctx: any) => { const usage: Usage = { provider: event.provider ?? ctx.modelProviderId, model: event.model ?? ctx.modelId, input: n(event.usage?.input), output: n(event.usage?.output), total: n(event.usage?.total), ts: Date.now(), sessionKey: ctx.sessionKey }; recentOutputs.push(usage); if (usage.sessionKey) recentBySession.set(usage.sessionKey, usage); while (recentOutputs.length > 80) recentOutputs.shift(); }, { name: "discord-output-metrics-footer-llm-output ...[truncated 2809 chars]- Remediation
View remediation
