Session Persistence
Medium
- Category
- Rogue Agent
- Content
## What this skill sends where Worth knowing before you run a debate: **the brief you write in step 1 is sent verbatim to a model hosted by another vendor.** That is the whole mechanism — there is no way to get cross-vendor adversarial value without it. - The brief goes to whichever channel you selected (OpenAI through the Codex CLI, xAI through the Cursor CLI, or whichever backend you configured for handoff). Write it accordingly: it should carry the argument, not your secrets. - Nothing else leaves your machine. This skill reads the brief you wrote and the attacker's replies. It does not scan your repository, collect telemetry, or send anything to a destination you did not configure.
- Confidence
- 96% confidence
- Finding
- This skill explicitly instructs the operator to send a user-prepared brief verbatim to a third-party model hosted by another vendor. Even though the document warns not to include secrets, the mechanism creates a real data-exfiltration boundary: sensitive source content, internal plans, or regulated data could be disclosed externally if a user includes them in the brief or attached file paths/material. The skill context increases risk because cross-vendor transfer is the core behavior, not an incidental side effect.
