T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:43- Finding
Claude Code Runs with Permission Controls Disabled
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill coherently delegates coding work to background agents, but it requires Claude Code to run with permission safeguards disabled and gives workers broad unattended execution authority.
Install only if you are comfortable with autonomous background coding agents operating in trusted, isolated repositories. Avoid using the Claude Code path unless you intentionally accept disabled permission prompts, and prefer sandboxed workdirs with minimal environment secrets and trusted notification route values.
SKILL.md:43Claude Code Runs with Permission Controls Disabled
SKILL.md:54Untrusted Notification Values Can Be Embedded in a Shell Command
The skill explicitly instructs use of claude --permission-mode bypassPermissions --print without any accompanying user-facing warning, approval step, or limitation on what the spawned worker may do. In a skill whose purpose is delegating coding work as a background agent, this increases risk because the worker can perform filesystem or command actions without normal permission prompts, making accidental destructive changes or unsafe execution easier.
No suspicious patterns detected.