other
- Location
SKILL.md:13- Finding
Unconsented Profiling of User Interests from Conversation History
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 13–14
Vulnerability Type:other: Sensitive Conversation-History Profiling
Risk Level: MediumVulnerable Code Snippet:
markdown ### 1. Analyze Interests All the news conllected news should match user's interests. User's interests can be summarized from recent memory and conversation history. At least **three** main interests should be offered.Technical Analysis
The skill directs the agent to infer a user's interests from recent memory and conversation history. This processing is not limited to information supplied in the current request, and the instructions neither require consent nor establish boundaries concerning which historical data may be inspected.
Requiring at least three inferred interests may encourage the agent to derive additional categories even when the current interaction provides insufficient context. Historical conversations can contain private, sensitive, or context-specific information that the user did not intend to reuse for news personalization.
The skill does not explicitly require transmitting conversation history to external news sources. The primary risk is unauthorized contextual profiling and disclosure of inferred interests in the generated response.
Attack Path
- A user invokes the personalized news skill without explicitly specifying topics.
- The skill instructs the agent to inspect recent memory and conversation history.
- The agent extracts or infers at least three interests, potentially including sensitive subjects from unrelated prior conversations.
- The agent uses those inferred interests to select news and includes the interest categories in its output.
- Anyone able to view the response may learn private interests or prior conversational themes that the user did not intend to disclose.
Impact Assessment
The issue does not grant operating-system privileges, execute code, or directly expose credentials. Its scope is ...[truncated 357 chars]
- Remediation
View remediation
Remediation Suggestions
- Use interests explicitly supplied in the current request by default.
- Obtain affirmative user consent before accessing conversation history or persistent memory.
- Present inferred interests to the user for confirmation before retrieving news.
- Inspect only the minimum relevant context and avoid deriving sensitive categories such as health, religion, politics, finances, or sexuality unless explicitly requested.
- Do not include inferred personal attributes in output unless necessary and approved by the user.
- Define clear retention, disclosure, and context-isolation rules for information derived from conversation history.
