T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:38- Finding
Overly Broad AWS Read Permissions Presented as Minimum Required Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 38–49
Vulnerability Type: Excessive IAM permissions and violation of least privilege
Risk Level: MediumThe Skill presents the following IAM policy as the minimum permissions required to run its documented AWS CLI commands:
json { "Version": "2012-10-17", "Statement": [{ "Effect": "Allow", "Action": ["config:Describe*", "config:Get*", "config:Select*", "securityhub:GetFindings", "iam:GetPolicy", "iam:ListPolicies"], "Resource": "*" }] }Technical Analysis
The wildcard permissions
config:Describe*,config:Get*, andconfig:Select*authorize substantially more AWS Config read operations than the three documented commands require. In addition,iam:GetPolicyandiam:ListPoliciesare not used by any command documented in the Skill.The stated workflows require only the actions corresponding to these operations:
config:DescribeComplianceByConfigRulesecurityhub:GetFindingsconfig:SelectResourceConfig
Presenting broader permissions as the minimum required policy violates the principle of least privilege. Although these are read-only permissions, they can expose extensive account configuration, compliance posture, resource metadata, and IAM policy information. Such information can facilitate security reconnaissance and help identify weak controls, sensitive resources, or potential privilege-escalation paths.
Attack Path
- A user trusts the Skill's assertion that the supplied policy represents the minimum required access.
- The user attaches the policy to an IAM principal, role, or automation environment.
- That principal receives wildcard AWS Config read permissions and unnecessary IAM policy-enumeration permissions.
- If the principal's credentials or execution context are compromised, an attacker can invoke additional permitted APIs beyond the documented workflow.
- The attacker ...[truncated 1210 chars]
- Remediation
View remediation
Remediation Suggestions
Replace wildcard action families with the exact permissions used by the documented commands:
json { "Version": "2012-10-17", "Statement": [ { "Sid": "ExportComplianceAnalysisData", "Effect": "Allow", "Action": [ "config:DescribeComplianceByConfigRule", "config:SelectResourceConfig", "securityhub:GetFindings" ], "Resource": "*" } ] }Additional hardening measures:
- Remove
iam:GetPolicyandiam:ListPoliciesfrom the baseline policy because the documented commands do not use them. - If IAM policy analysis is later added, document that workflow separately and provide an optional, narrowly scoped policy.
- Retain
"Resource": "*"only for API actions that do not support resource-level IAM restrictions; otherwise, restrict access to explicit resource ARNs. - Apply permission boundaries and AWS Organizations service control policies where appropriate.
- Use a dedicated short-lived role for data exports rather than attaching these permissions to a persistent user.
- Restrict Security Hub access to required regions and export only the fields needed for the compliance assessment.
- Validate the effective permissions with IAM Access Analyzer or policy simulation before deployment.
- Update the documentation so that permissions are described accurately as required or optional rather than collectively labeled as minimum access.
- Remove
