T05 · Unauthorized Access and Privilege Escalation
- Location
references/evaluate-page.md:102- Finding
Unvalidated goal_slug Allows Workspace Path Traversal
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This browsing skill is purpose-built but needs Review because it automatically keeps durable records of broad browsing activity and has under-scoped workspace write paths.
Install only if you are comfortable with this skill saving your goals, constraints, visited-page metadata, extracted findings, recommendations, and history into workspace files. Avoid using it for sensitive health, legal, financial, employment, or private research unless the publisher adds clear retention controls, a no-save mode, goal_slug validation, and stronger handling of untrusted webpage text.
references/evaluate-page.md:102Unvalidated goal_slug Allows Workspace Path Traversal
references/evaluate-page.md:109Untrusted Web Content Is Propagated into Persistent Agent Memory
The skill explicitly states that it persists all session data to the workspace, but it provides no user-facing notice, consent mechanism, or data-minimization boundary. Because this skill supports broad goal types including health, career, and decision-making, it may store sensitive browsing goals, page evaluations, and summaries without the user realizing durable local records are being created.
Persisting all session data creates a retention risk because the stored material can include raw goals, criteria, page findings, and possibly sensitive inferences in natural language. In a multi-domain browsing assistant, those records may reveal private interests or circumstances long after the session ends, increasing exposure if the workspace is accessed by other tools, users, or processes.
The workflow mandates writes before every response, making storage automatic and unavoidable for all operations. This is dangerous because even simple evaluation requests will silently create persistent artifacts, increasing the chance that sensitive user intent, browsing context, or derived conclusions are retained without informed consent.
Requiring reads and writes of all persistence artifacts before responding operationalizes comprehensive retention as part of normal execution. This makes over-collection likely, because every interaction is funneled into durable state and logs whether or not persistence is needed for the user's immediate task.
The defined file layout includes append-only history, live status, latest-session summaries, full session state, and immutable event logs, which together create broad, accumulating records of user activity. This is especially risky in the stated context because goals may involve health, career, travel, or other personal topics, so the storage design amplifies privacy exposure beyond what is necessary for basic operation.
The skill explicitly requires persistent writes to multiple workspace and memory files, including session history and active-goal state, without any indication of user consent, approval gating, or notice that data will be stored long-term. In a browsing assistant context, this can silently retain potentially sensitive goal text, constraints, findings, and recommendations, creating privacy, integrity, and auditability risks if the user did not intend persistent storage.
The skill explicitly requires persistent storage of every page evaluation, including low-relevance pages, full browsing history, and session state, without any mention of user consent, minimization, or retention limits. This can silently accumulate sensitive research activity, visited URLs, and extracted page-derived data in predictable workspace files, creating a privacy and data-governance risk.
The skill explicitly requires writing multiple files into the workspace, including an active session pointer and session state, without any mention of user notification, consent, or conditional gating. Persisting data by default can create unintended state changes, leak sensitive goal/constraint data into durable storage, and make later agent behavior depend on hidden prior context.
The skill instructs persistent writes that change global session state (active-goal.json) and regenerate a memory file as part of a resume operation, but it provides no user warning, confirmation, or safety constraints around mutating workspace state. In a browsing assistant that persists cross-session context, this can unexpectedly overwrite the active goal pointer or session memory, causing state confusion, loss of prior context, or unintended continuation under the wrong goal.
The operation explicitly performs persistent writes to workspace files and notes that removed criteria lose coverage data permanently, but it does not require an explicit confirmation or user-facing warning before destructive changes are applied. In the context of a goal-tracking skill that persists session state, this creates a real risk of unintended data loss or silent state tampering if an agent invokes the operation based on ambiguous or adversarial input.