other
- Location
SKILL.md:383- Finding
Automatic Persistent Logging of User Search Activity
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:383-393
Vulnerability Type: Unnecessary persistent activity logging
Risk Level: LowComplete Vulnerable Snippet:
markdown 搜索完成后自动记录到 `memory/YYYY-MM-DD.md`: ```markdown ### 闲鱼搜索记录 **时间:** 2026-03-10 18:36 **关键词:** RTX 5090 **结果数量:** 10 条 **价格区间:** ¥1.74 万 - ¥1.90 万 **最低价商品:** [技嘉魔鹰 OC](https://www.goofish.com/item?id=1017187960312) **筛选条件:** 个人闲置/单一价格/排除商家text ### Technical Analysis The Skill instructs the Agent to automatically write every completed search to a persistent daily memory file. The retained data includes the search timestamp, user query, price range, selected listing URL, result count, and filtering preferences. Persisting this information is not necessary for the Skill's primary function of searching for marketplace listings and returning results. The instruction provides no consent mechanism, opt-out option, data-minimization policy, retention period, access restriction, or deletion process. Consequently, potentially sensitive purchasing interests and preferences may accumulate across sessions. This behavior is not classified as Agent Memory Poisoning because the retained content is activity history rather than attacker-controlled instructions intended to alter future Agent behavior. ### Attack Path 1. A user submits a marketplace query that may reveal a sensitive interest, purchasing intention, budget, or location preference. 2. The Skill performs the search and applies the requested filters. 3. After completing the search, the Skill automatically writes the query and associated result metadata to `memory/YYYY-MM-DD.md`. 4. The records persist beyond the current invocation. 5. Any workspace component or user with permission to read that memory location may later inspect the retained search history. No external exfiltration path or unauthorized privilege gain was identified. ### Impact Assessment The iss ...[truncated 458 chars]- Remediation
View remediation
Remediation Suggestions
- Disable persistent search-history logging by default.
- Obtain explicit user consent before storing any query or result metadata.
- Provide a clear per-search opt-out and a global configuration option to disable history.
- Apply data minimization by omitting exact queries, direct listing links, timestamps, locations, and price preferences unless specifically required.
- Define a short retention period and automatically delete expired records.
- Provide users with commands or documented procedures to inspect and delete stored history.
- Restrict access to stored records using the narrowest available filesystem permissions.
- Avoid persisting searches identified as sensitive; when history is needed, prefer a redacted or aggregated record.
