T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:51- Finding
Excessive Default Attendee Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 51–60
Vulnerability Type: Excessive default permissions that violate least privilege
Risk Level: MediumComplete Code Snippet:
markdown ### 2. 参会人权限(attendee_ability) 工具已默认设置 `attendee_ability: "can_modify_event"`,参会人可以编辑日程和管理参与者。 | 权限值 | 能力 | |--------|------| | `none` | 无权限 | | `can_see_others` | 可查看参与人列表 | | `can_invite_others` | 可邀请他人 | | `can_modify_event` | 可编辑日程(推荐) |The policy is reinforced at lines 174 and 177:
markdown | **参会人看不到其他参会人** | `attendee_ability` 权限不足 | 工具已默认设置 `can_modify_event` | | **修改日程报权限错误** | 当前用户不是组织者,且日程未设置可编辑权限 | 确保日程创建时设置了 `attendee_ability: "can_modify_event"` |Technical Analysis
The Skill states that
attendee_abilitydefaults tocan_modify_eventand recommends this setting generally. This permission allows attendees to edit an event and manage its participants, although ordinary attendance does not require either capability.The documented availability of narrower settings—
none,can_see_others, andcan_invite_others—shows that the elevated permission is not technically necessary for all events. Assigning the highest documented attendee permission by default violates the principle of least privilege.This is especially risky because the Skill supports user, group, meeting-room, and external-email attendee types. An unintended, untrusted, or compromised attendee could receive modification privileges without a separate authorization decision by the organizer.
Attack Path
- An organizer creates a calendar event using the Skill.
- The tool applies the documented default
attendee_ability: "can_modify_event". - An untrusted or compromised account is included as an attendee, directly or through a supported attendee mechanism.
- That attendee uses the granted capability to modify event details or manage the participant list.
- Other attendees receive or r ...[truncated 824 chars]
- Remediation
View remediation
Remediation Suggestions
- Change the default
attendee_abilitytonone, or to the narrowest permission necessary for the requested operation. - Require explicit organizer confirmation before assigning
can_modify_event. - Do not describe
can_modify_eventas the generally recommended setting; document it as a high-privilege option for trusted collaborators only. - If attendees only need visibility into the participant list, use
can_see_others. - If attendees only need to invite others, use
can_invite_othersand clearly communicate that capability. - Display a warning before granting modification rights, identifying the affected event and attendees.
- Validate attendee identity and type before granting elevated permissions, with particular caution for external addresses and group-based attendees.
- Add tests or policy checks that reject implicit
can_modify_eventassignments unless an explicit authorization flag is present. - Update the troubleshooting guidance at lines 174 and 177 so it does not recommend broad modification privileges as the default solution to visibility or authorization problems.
- Change the default
