T05 · Unauthorized Access and Privilege Escalation
- Location
skill_wrapper.py:24- Finding
Undeclared Arbitrary Local Process Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:6;skill_wrapper.py:24-29;skill_wrapper.py:71-73
Vulnerability Type: Undeclared command-execution capability that exceeds the manifest's stated permissions
Risk Level: MediumVulnerable Code
SKILL.md:6declares only file access:yaml permissions: ["file.read", "file.write"]skill_wrapper.py:24-29executes a caller-selected process:python result = subprocess.run( command, capture_output=True, text=True, timeout=60 )skill_wrapper.py:71-73derives that process and its arguments from the unrestricted--callvalue:python command = args.call.split() result = run_skill(args.skill, command)Technical Analysis
The Skill manifest declares only file read and write permissions, but the implementation can invoke any executable accessible to the current user. This violates least privilege and prevents consumers from accurately assessing the Skill's effective authority.
The implementation does not use
shell=True, so shell metacharacters such as pipes and command substitutions are not interpreted directly. This reduces conventional shell-injection exposure, but it does not remove the underlying arbitrary process-execution capability: the first token supplied through--callselects the executable, and the remaining tokens become its arguments.Attack Path
- An attacker, untrusted workflow, or compromised agent influences the value passed to
--call. args.call.split()converts the supplied string into an executable name and argument list.run_skill()passes that list directly tosubprocess.run().- The selected local executable runs with the privileges and environment of the user invoking the wrapper.
- The process can access files, credentials, network resources, and operating-system interfaces available to that user, irrespective of the manifest's narrower pe ...[truncated 744 chars]
- An attacker, untrusted workflow, or compromised agent influences the value passed to
- Remediation
View remediation
Remediation Suggestions
- Explicitly declare process-execution capability in the Skill manifest so users and policy engines can make an informed authorization decision.
- Replace unrestricted executable selection with an allowlist of approved programs.
- Validate arguments for each approved program using command-specific schemas; reject unexpected options, paths, and argument counts.
- Do not construct executable requests from untrusted natural-language or task input without an explicit confirmation boundary.
- Resolve and verify executable paths rather than relying on an attacker-influenced
PATH. - Run wrapped processes in a least-privilege sandbox with a restricted environment, filesystem view, network policy, and resource limits.
- Continue using argument-vector execution without
shell=True. - Consider changing the API to accept a structured command identifier and validated arguments rather than a free-form
--callstring.
