T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/cli.ts:130- Finding
Generic Signed Request Command Bypasses the Intended Read-Only Security Boundary
- Content
View full analysis
Vulnerability Details
File Location:
scripts/cli.ts:36-40,scripts/cli.ts:130-153; related security boundary inSKILL.md:23-29
Vulnerability Type: Arbitrary authenticated API request / read-only policy bypass
Risk Level: High
Category: T05: Unauthorized Access and Privilege EscalationVulnerable Code:
ts case 'request': await handleRequest(rest); return;ts async function handleRequest(args: string[]): Promise<void> { const [method, path, ...rest] = args; if (!method || !path) { throw new Error('Usage: request <METHOD> <PATH> [--body-json JSON] [--query-json JSON] [--node NODE]'); } const { flags } = parseArgs(rest); const client = createClient(flags); const body = parseOptionalJson(flags['body-json']); const query = parseOptionalJson(flags['query-json']); const operateNode = readOptionalString(flags.node); const response = await client.request({ method: method.toUpperCase() as 'GET' | 'POST' | 'PUT' | 'PATCH' | 'DELETE', path, body, query: isRecord(query) ? (query as Record<string, string | number | boolean | null | undefined>) : undefined, operateNode, }); printResponse(response.status, response.data, response.rawBody); }Technical Analysis
The Skill documentation presents currently implemented operations as query-oriented and instructs the agent not to fabricate write workflows. Mutation endpoints are described as reserved for future controlled expansion. However, the
requestCLI command accepts a caller-provided HTTP method, API path, request body, query parameters, and node selection, and then signs the request using the configured 1Panel API key.No endpoint allowlist, read-only method restriction, mutation confirmation mechanism, or authorization policy is applied. The TypeScript assertion:
ts method.toUpperCase() as 'GET' | 'POST' | 'PUT' | 'PATCH ...[truncated 1728 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the generic
requestcommand from the agent-facing CLI. - If raw requests are required for development, move them to a separate administrative executable that is not exposed as a Skill action.
- Enforce an explicit allowlist of approved API paths and methods. Match normalized paths rather than raw caller strings.
- Restrict the current agent-facing command to approved read operations. Do not assume that
POSTis safe merely because some search endpoints use it; authorize method-and-path pairs together. - Validate HTTP methods at runtime instead of relying on a TypeScript assertion.
- Require explicit human confirmation and separate credentials before permitting future mutations.
- Use a dedicated least-privilege API key whose server-side permissions prevent mutation even if client-side controls are bypassed.
- Add security tests proving that unregistered endpoints and reserved mutation paths are rejected.
- Remove the generic
