T05 · Unauthorized Access and Privilege Escalation
- Location
moltflow-onboarding/SKILL.md:38- Finding
Read-Only Onboarding Workflow Requires Write-Capable API Key Scopes
- Content
View full analysis
Vulnerability Details
File Location:
moltflow-onboarding/SKILL.md, lines 38-43
Vulnerability Type: Excessive privileges and violation of least privilege
Risk Level: HighVulnerable code:
markdown ## Required API Key Scopes | Scope | Access | |-------|--------| | `sessions` | `manage` | | `messages` | `send` |The requested permissions conflict with the module's explicitly read-only behavior:
markdown ## Step 1: Fetch Account Data (Read-Only) Gather data from these read-only endpoints. All are `GET` requests authenticated via `X-API-Key: $MOLTFLOW_API_KEY` header. Base URL: `https://apiv2.waiflow.app/api/v2`. | Endpoint | Data | Full Docs | |----------|------|-----------| | `GET /users/me` | Account & plan | moltflow-admin SKILL.md | | `GET /sessions` | WhatsApp sessions | moltflow SKILL.md | | `GET /groups` | Monitored groups | moltflow SKILL.md | | `GET /custom-groups` | Custom groups | moltflow-outreach SKILL.md | | `GET /webhooks` | Webhooks | moltflow SKILL.md | | `GET /reviews/collectors` | Review collectors | moltflow-reviews SKILL.md | | `GET /tenant/settings` | Tenant settings | moltflow-admin SKILL.md | | `GET /scheduled-messages` | Scheduled messages | moltflow-outreach SKILL.md | | `GET /usage/current` | Usage stats | moltflow-admin SKILL.md | | `GET /leads` | Existing leads | moltflow-leads SKILL.md | | `GET /messages/chats/{session_id}` | Chats (per session) | moltflow SKILL.md |Technical Analysis
The onboarding Skill declares itself a read-only account-health and growth-report workflow. Its documented operations use HTTP
GETrequests to retrieve account metadata, usage, sessions, leads, and chat summaries. Nevertheless, it asks users to grantsessions:manageandmessages:sendcapabilities.sessions:managecan authorize state-changing session operations, whilemessages:sendpermits outbound WhatsApp communication. Neither p ...[truncated 1416 chars]- Remediation
View remediation
Remediation Suggestions
- Replace
sessions:managewithsessions:read. - Replace
messages:sendwithmessages:read. - Document every additional read scope needed for the listed endpoints, such as read-only scopes for groups, custom groups, webhooks, reviews, settings, schedules, usage, and leads.
- Provide a dedicated onboarding or account-health scope that cannot invoke any state-changing endpoint.
- Reject write-capable credentials when executing the read-only onboarding workflow, or prominently warn the user and request a replacement read-only key.
- Add automated tests verifying that all onboarding requests use safe HTTP methods and that its key cannot send messages, alter sessions, update settings, or modify resources.
- Use a short-lived key limited to the current tenant and rotate or revoke it after the report is generated.
- Replace
