T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:3- Finding
Overprivileged Full API Scope Permitted for Platform Connection
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 3
Vulnerability Type: Excessive API authorization scope
Risk Level: MediumComplete Code Snippet:
yaml description: Connect Polymarket to your CAI account using platforms_supported_list and platform_one_click_register when F-16 applies; wallet derivation via catalog driver. Requires platform or full API scope. Powered by CAI.com.Technical Analysis
The skill expressly permits use of a credential with either platform scope or full API scope. The documented workflow requires platform discovery, account registration, profile or balance retrieval, and vault credential metadata access, but it does not identify any operation that requires unrestricted account-wide API authorization.
Allowing full API scope violates the principle of least privilege. The skill also does not instruct the agent to prefer platform scope, reject unnecessarily broad credentials, or obtain separate user approval before escalating authorization.
Attack Path
- A user follows the skill and authorizes a CAI API credential with full API scope.
- The credential becomes available to the agent or associated integration.
- The agent environment, integration, or credential is compromised or misused.
- The attacker invokes API functionality outside the Polymarket connection workflow using the unnecessarily broad authorization.
- Unrelated CAI resources or operations accessible to that credential may be exposed or modified.
Impact Assessment
Successful exploitation could grant access beyond the Polymarket integration's legitimate requirements. The exact accessible resources depend on CAI's definition of full API scope, which is not specified in the audited file. The potential blast radius nevertheless exceeds the documented platform-linking task and could include unrelated account data or operations available through the same API credential.
- Remediation
View remediation
Remediation Suggestions
- Require the narrowest platform-specific authorization scope by default.
- Remove the statement that full API scope is an acceptable general alternative.
- Enumerate the exact permissions needed for platform discovery, registration, profile access, balance access, and credential metadata access.
- Validate the credential's effective scope before beginning the workflow and reject credentials with unnecessary permissions.
- If an operation genuinely requires broader access, request it through a separate, explicit, purpose-bound user consent step.
- Use short-lived, revocable credentials and provide instructions for revoking access after linking.
