T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/arbiter.py:705- Finding
Path Traversal in Skill Revocation Allows Arbitrary Directory Deletion
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This local auditing skill also includes high-impact commands that can quarantine or delete other skills, including a path-handling flaw that can reach outside the intended skills directory.
Review this carefully before installing. It is not just a passive auditor: it can rename, quarantine, and permanently remove other skills, and the revoke command needs path validation and confirmation safeguards before it should be trusted in a real workspace. I found no evidence of network exfiltration, remote code loading, credential theft, or hidden background persistence.
scripts/arbiter.py:705Path Traversal in Skill Revocation Allows Arbitrary Directory Deletion
scripts/arbiter.py:279Unsupported Script and Instruction Formats Can Bypass Security Enforcement
The revoke path can permanently remove other installed skills by copying them to a vault and then recursively deleting the original directory. In a multi-skill workspace, this gives the tool powerful destructive capability over peer components that is not necessary for passive auditing and can cause denial of service or irreversible loss if triggered accidentally or abusively.
The skill advertises and documents code that audits installed skills for network, subprocess, file I/O, environment variables, and unsafe operations, but its manifest declares no explicit tool scope or permissions. That mismatch means the skill likely requires broad local access without transparent permission boundaries, increasing the risk of over-privileged execution and making it harder for users or platforms to evaluate what the skill can actually do.
The skill presents itself as a permission auditor, but its documented scope includes active countermeasures such as subversion, quarantine, revocation, and defense sweeps. That mismatch matters because users may grant trust to an auditing tool that can also modify or remove other skills, increasing the chance of unsafe deployment and abuse.
The revocation flow performs destructive filesystem operations without any confirmation prompt, interlock, or dry-run. This makes operator mistakes, malicious invocation, or accidental targeting much more damaging because a single command can delete a skill directory immediately.
The protect sweep automatically renames skill directories to quarantine them based on pattern matches and policy evaluation. Because the scanner is heuristic and can generate false positives, auto-disabling installed skills can be abused or can unexpectedly break the environment, turning an audit tool into an enforcement mechanism without per-skill confirmation.
The revoke docstring claims the skill is 'moving it to the quarantine vault first,' implying a simple relocation. The implementation instead creates metadata, copies the entire tree into a vault with shutil.copytree, and then deletes the original with shutil.rmtree, which is a different and more destructive sequence than described.
Detected: suspicious.dynamic_code_execution