T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:34- Finding
Mandatory Persistent Collection of Sensitive Operational Metadata Without Explicit Consent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This VS Code helper is coherent, but it automatically keeps shared local records about projects, hosts, and access pointers without asking first.
Install only if you are comfortable with the skill maintaining a local Clawic knowledge base about your VS Code setup, repositories, extensions, remote hosts, and access-pointer locations. Review or disable the automatic memory behavior for sensitive work, and periodically inspect and prune ~/Clawic/data/vscode/, ~/Clawic/data/servers/, and ~/Clawic/data/projects/.
SKILL.md:34Mandatory Persistent Collection of Sensitive Operational Metadata Without Explicit Consent
SKILL.md:34Cross-Session Memory Poisoning Through Automatically Reloaded Artifacts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**Remote hosts go to the shared inventory `~/Clawic/data/servers/servers.md`**, not here: one file holds machines from every provider, so "which box am I editing on" answers itself whoever provisioned it. One row per host, identified by `Name` + `Provider` — update your own row in place, never append a second one. A tracked codebase goes to the shared `~/Clawic/data/projects/<project>.md` by name; the editor-shaped facts about it stay here.
**No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, not in text the user pastes in to be saved. A pasted `settings.json`, `devcontainer.json`, `tasks.json` or terminal-env block is the densest source of secrets in this domain: strip the value and store the pointer — `env:GITHUB_TOKEN`, `keychain:npm-publish`, `1password:Work/Registry/ci`, `file:~/.ssh/id_ed25519`. If data sits at an old location (`~/vscode/` or `~/clawic/vscode/`), move it to `~/Clawic/data/vscode/`, and say in one line that you moved it and from where.
Almost every VS Code problem is one of five things: a setting resolved at the wrong scope, an extension doing something you did not attribute to it, a path that means something different to the debugger than to you, a process boundary (extension host, remote server, shell), or trust. Name which one before proposing a fix, and give the file, the key, and the value that changes. Work from defaults immediately: never open with questions about their OS, their extensions, or how proactive to be. The one exception to silence is `os_family` — while it is unset, give shortcuts in both `Cmd` and `Ctrl` form rather than asking. That is a statement, not a question. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals) → the Configuration table default.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**Remote hosts go to the shared inventory `~/Clawic/data/servers/servers.md`**, not here: one file holds machines from every provider, so "which box am I editing on" answers itself whoever provisioned it. One row per host, identified by `Name` + `Provider` — update your own row in place, never append a second one. A tracked codebase goes to the shared `~/Clawic/data/projects/<project>.md` by name; the editor-shaped facts about it stay here.
**No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, not in text the user pastes in to be saved. A pasted `settings.json`, `devcontainer.json`, `tasks.json` or terminal-env block is the densest source of secrets in this domain: strip the value and store the pointer — `env:GITHUB_TOKEN`, `keychain:npm-publish`, `1password:Work/Registry/ci`, `file:~/.ssh/id_ed25519`. If data sits at an old location (`~/vscode/` or `~/clawic/vscode/`), move it to `~/Clawic/data/vscode/`, and say in one line that you moved it and from where.
Almost every VS Code problem is one of five things: a setting resolved at the wrong scope, an extension doing something you did not attribute to it, a path that means something different to the debugger than to you, a process boundary (extension host, remote server, shell), or trust. Name which one before proposing a fix, and give the file, the key, and the value that changes. Work from defaults immediately: never open with questions about their OS, their extensions, or how proactive to be. The one exception to silence is `os_family` — while it is unset, give shortcuts in both `Cmd` and `Ctrl` form rather than asking. That is a statement, not a question. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals) → the Configuration table default.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**Remote hosts go to the shared inventory `~/Clawic/data/servers/servers.md`**, not here: one file holds machines from every provider, so "which box am I editing on" answers itself whoever provisioned it. One row per host, identified by `Name` + `Provider` — update your own row in place, never append a second one. A tracked codebase goes to the shared `~/Clawic/data/projects/<project>.md` by name; the editor-shaped facts about it stay here.
**No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, not in text the user pastes in to be saved. A pasted `settings.json`, `devcontainer.json`, `tasks.json` or terminal-env block is the densest source of secrets in this domain: strip the value and store the pointer — `env:GITHUB_TOKEN`, `keychain:npm-publish`, `1password:Work/Registry/ci`, `file:~/.ssh/id_ed25519`. If data sits at an old location (`~/vscode/` or `~/clawic/vscode/`), move it to `~/Clawic/data/vscode/`, and say in one line that you moved it and from where.
Almost every VS Code problem is one of five things: a setting resolved at the wrong scope, an extension doing something you did not attribute to it, a path that means something different to the debugger than to you, a process boundary (extension host, remote server, shell), or trust. Name which one before proposing a fix, and give the file, the key, and the value that changes. Work from defaults immediately: never open with questions about their OS, their extensions, or how proactive to be. The one exception to silence is `os_family` — while it is unset, give shortcuts in both `Cmd` and `Ctrl` form rather than asking. That is a statement, not a question. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals) → the Configuration table default.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**Remote hosts go to the shared inventory `~/Clawic/data/servers/servers.md`**, not here: one file holds machines from every provider, so "which box am I editing on" answers itself whoever provisioned it. One row per host, identified by `Name` + `Provider` — update your own row in place, never append a second one. A tracked codebase goes to the shared `~/Clawic/data/projects/<project>.md` by name; the editor-shaped facts about it stay here.
**No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, not in text the user pastes in to be saved. A pasted `settings.json`, `devcontainer.json`, `tasks.json` or terminal-env block is the densest source of secrets in this domain: strip the value and store the pointer — `env:GITHUB_TOKEN`, `keychain:npm-publish`, `1password:Work/Registry/ci`, `file:~/.ssh/id_ed25519`. If data sits at an old location (`~/vscode/` or `~/clawic/vscode/`), move it to `~/Clawic/data/vscode/`, and say in one line that you moved it and from where.
Almost every VS Code problem is one of five things: a setting resolved at the wrong scope, an extension doing something you did not attribute to it, a path that means something different to the debugger than to you, a process boundary (extension host, remote server, shell), or trust. Name which one before proposing a fix, and give the file, the key, and the value that changes. Work from defaults immediately: never open with questions about their OS, their extensions, or how proactive to be. The one exception to silence is `os_family` — while it is unset, give shortcuts in both `Cmd` and `Ctrl` form rather than asking. That is a statement, not a question. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals) → the Configuration table default.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**Remote hosts go to the shared inventory `~/Clawic/data/servers/servers.md`**, not here: one file holds machines from every provider, so "which box am I editing on" answers itself whoever provisioned it. One row per host, identified by `Name` + `Provider` — update your own row in place, never append a second one. A tracked codebase goes to the shared `~/Clawic/data/projects/<project>.md` by name; the editor-shaped facts about it stay here.
**No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, not in text the user pastes in to be saved. A pasted `settings.json`, `devcontainer.json`, `tasks.json` or terminal-env block is the densest source of secrets in this domain: strip the value and store the pointer — `env:GITHUB_TOKEN`, `keychain:npm-publish`, `1password:Work/Registry/ci`, `file:~/.ssh/id_ed25519`. If data sits at an old location (`~/vscode/` or `~/clawic/vscode/`), move it to `~/Clawic/data/vscode/`, and say in one line that you moved it and from where.
Almost every VS Code problem is one of five things: a setting resolved at the wrong scope, an extension doing something you did not attribute to it, a path that means something different to the debugger than to you, a process boundary (extension host, remote server, shell), or trust. Name which one before proposing a fix, and give the file, the key, and the value that changes. Work from defaults immediately: never open with questions about their OS, their extensions, or how proactive to be. The one exception to silence is `os_family` — while it is unset, give shortcuts in both `Cmd` and `Ctrl` form rather than asking. That is a statement, not a question. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals) → the Configuration table default.
Referenced artifact was not completely inspected
ser → Remote → Workspace → Folder, then language-specific inside it (Rule 1) | `settings.md` |
Referenced artifact was not completely inspected
ser → Remote → Workspace → Folder, then language-specific inside it (Rule 1) | `settings.md` |
Referenced artifact was not completely inspected
ser → Remote → Workspace → Folder, then language-specific inside it (Rule 1) | `settings.md` |
Referenced artifact was not completely inspected
ser → Remote → Workspace → Folder, then language-specific inside it (Rule 1) | `settings.md` |
Referenced artifact was not completely inspected
ser → Remote → Workspace → Folder, then language-specific inside it (Rule 1) | `settings.md` |
Referenced artifact was not completely inspected
d` + `beginsPattern`/`endsPattern`; matcher `fileLocation` is the usual miss | `tasks.md` |
Referenced artifact was not completely inspected
d` + `beginsPattern`/`endsPattern`; matcher `fileLocation` is the usual miss | `tasks.md` |
Referenced artifact was not completely inspected
d` + `beginsPattern`/`endsPattern`; matcher `fileLocation` is the usual miss | `tasks.md` |
Referenced artifact was not completely inspected
| Snippets, suggestions, multi-cursor, or Emmet misbehaving | Suggest settings, snippet scope, `editor.multiCursorModifier` side effects | `editing.md` |
Referenced artifact was not completely inspected
| Snippets, suggestions, multi-cursor, or Emmet misbehaving | Suggest settings, snippet scope, `editor.multiCursorModifier` side effects | `editing.md` |
Referenced artifact was not completely inspected
| Snippets, suggestions, multi-cursor, or Emmet misbehaving | Suggest settings, snippet scope, `editor.multiCursorModifier` side effects | `editing.md` |
Referenced artifact was not completely inspected
| Multi-root workspace, or per-folder settings ignored | `.code-workspace` semantics and which settings survive at folder scope | `workspaces.md` |
Referenced artifact was not completely inspected
| Multi-root workspace, or per-folder settings ignored | `.code-workspace` semantics and which settings survive at folder scope | `workspaces.md` |
Referenced artifact was not completely inspected
| Multi-root workspace, or per-folder settings ignored | `.code-workspace` semantics and which settings survive at folder scope | `workspaces.md` |
Referenced artifact was not completely inspected
| Multi-root workspace, or per-folder settings ignored | `.code-workspace` semantics and which settings survive at folder scope | `workspaces.md` |
Referenced artifact was not completely inspected
| Multi-root workspace, or per-folder settings ignored | `.code-workspace` semantics and which settings survive at folder scope | `workspaces.md` |
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. A pasted `settings.json`, `tasks.json`, `devcontainer.json`, `launch.json` `env` block or terminal environment block is the densest source of secrets in this domain: strip each value **before** writing and leave its pointer in place, in this shape: `<kind>:<locator>`.
`env:GITHUB_TOKEN` · `keychain:npm-publish` · `1password:Work/Registry/ci` · `bitwarden:Dev/Sentry` · `vault:secret/dev/api` · `profile:work` · `file:~/.ssh/id_ed25519` · `file:~/.npmrc`
In a text, the pointer goes where the value was: `"GITHUB_TOKEN": "<env:GITHUB_TOKEN>"`. Say in one line that you did it.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
In this domain — **not secrets, keep them**: extension ids and versions, setting keys, task and launch labels, problem-matcher regexes, file and folder paths, workspace and profile names, host names and SSH aliases, port numbers, interpreter and toolchain paths, marketplace names, git remote URLs without credentials, keyboard shortcuts, glibc and editor version numbers.
**Secrets, strip them**: personal access tokens and API keys in `terminal.integrated.env.*`, `tasks.json` `options.env`, `launch.json` `env`, or `devcontainer.json` `containerEnv`/`remoteEnv`; registry tokens in `.npmrc`/`.pypirc` the user pastes; `settings.json` keys ending in `apiKey`, `token`, `secret`, or `password`; SSH private keys and passphrases; git remote URLs that embed a password; license keys; proxy URLs carrying credentials.
**Contents:** [config.yaml](#configyaml) · [memory.md](#memorymd) · [shared servers inventory](#shared-servers-inventory) · [shared projects box](#shared-projects-box) · [artifacts/](#artifacts) · [split-out files](#split-out-files)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
In this domain — **not secrets, keep them**: extension ids and versions, setting keys, task and launch labels, problem-matcher regexes, file and folder paths, workspace and profile names, host names and SSH aliases, port numbers, interpreter and toolchain paths, marketplace names, git remote URLs without credentials, keyboard shortcuts, glibc and editor version numbers.
**Secrets, strip them**: personal access tokens and API keys in `terminal.integrated.env.*`, `tasks.json` `options.env`, `launch.json` `env`, or `devcontainer.json` `containerEnv`/`remoteEnv`; registry tokens in `.npmrc`/`.pypirc` the user pastes; `settings.json` keys ending in `apiKey`, `token`, `secret`, or `password`; SSH private keys and passphrases; git remote URLs that embed a password; license keys; proxy URLs carrying credentials.
**Contents:** [config.yaml](#configyaml) · [memory.md](#memorymd) · [shared servers inventory](#shared-servers-inventory) · [shared projects box](#shared-projects-box) · [artifacts/](#artifacts) · [split-out files](#split-out-files)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Environment
macOS 15, arm64, VS Code stable, zsh with a `.zshrc` that prints a banner — shell-env resolution failed until it was guarded by `[[ -o interactive ]]`.
Corporate proxy needs `http.proxyStrictSSL: false` plus the CA in the system keychain; extension installs fail without it.
Linux workstation: `fs.inotify.max_user_watches` raised to 524288; below that the monorepo threw ENOSPC on open.
Right Alt remapped at the OS level — `alt+click` multi-cursor unavailable, so `editor.multiCursorModifier` is `ctrlCmd`.
Remote `build-1` runs Debian 12; anything older than glibc 2.28 cannot host the server (`vscode >=1.86`).
No suspicious patterns detected.