T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:98- Finding
Unrestricted Cross-Session Conversation Log Search
- Content
View full analysis
/sessions/*.jsonl ``` ``` Supporting instructions also state that the skill can search the user's “complete conversation history” and identify the session directory containing full conversation transcripts. ### Technical Analysis The skill explicitly instructs the agent to search every JSONL transcript under the agent's session directory. This operation is not limited to the particular historical conversation relevant to the user's request. No instructions require: - Explicit authorization before accessing historical logs. - Restriction to a user-selected session. - Validation that discovered sessions belong to the requesting user or context. - Exclusion of unrelated conversations or tool results. - Redaction of credentials, personal information, or other sensitive content. - Minimization of excerpts returned to the current conversation. Session transcripts can contain user messages, assistant responses, tool calls, tool results, operational metadata, and potentially secrets exposed during earlier tasks. Although the skill does not bypass operating-system permissions, it encourages using the agent's existing filesystem privileges beyond the minimum scope ordinarily necessary to answer a targeted historical-context request. This violates least-privilege and purpose-limitation principles. The provided command only returns matching file names, but it acts as a discovery step. Other commands documented in the same skill can subsequently extract full text from any discovered transcript. ### Attack Path 1. An attacker or untrusted participant asks the agent to recall historical information or search prior conversations for a broad phrase. 2. The request triggers t ...[truncated 1475 chars]- Remediation
View remediation
