T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:24- Finding
Unrestricted Delegated Execution Through Copilot CLI
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24–35 and 46–56
Vulnerability Type: Unrestricted tool, filesystem, and network permissions
Risk Level: HighVulnerable Code
text copilot -p \"Your prompt here\" --allow-all --silenttext - `--allow-all`: Enables all tools/paths/URLs (use `--yolo` for short). - `--silent`: Outputs only agent response. - `--model claude-sonnet-4.6` or `gpt-5.2` etc. to choose model. **In OpenClaw exec:**text exec: command: copilot -p 'Generate a Python script to...' --allow-all --silenttext ### Shell tasktext copilot -p 'List all .js files and summarize' --allow-alltext ### Code generationtext copilot -p 'Create a simple Express server in Node.js' --allow-all --silenttext ### File editstext copilot -p 'Add error handling to main.js' --allow-allTechnical Analysis
The Skill recommends
--allow-allas the standard invocation mode and identifies--yoloas its shorthand. According to the Skill itself, this option enables access to all tools, filesystem paths, and URLs. Such unrestricted authority is not necessary for ordinary code generation, source summarization, or narrowly scoped file edits and therefore violates least-privilege principles.Copilot is a delegated agent capable of selecting and executing tools based on prompts and contextual instructions. If its input or automatically loaded repository instructions are attacker-controlled, unrestricted access can turn an otherwise textual prompt-injection condition into command execution, arbitrary file access or modification, and outbound network communication. The use of
--silentcan further reduce operator visibility into the delegated activity, although it is not independently the source of the privilege issue.Attack Path
- A user invokes this Skill against a repository ...[truncated 1507 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
--allow-alland--yolofrom default commands, recommendations, and examples. - Require explicit, per-action approval for shell execution, file modification, and network access.
- Restrict filesystem permissions to the intended workspace and deny access to home-directory credentials, SSH material, cloud configuration, and unrelated repositories.
- Apply URL or domain allowlists and disable outbound network access when it is unnecessary.
- Separate read-only analysis from file-editing and shell-task workflows, granting each operation only the tools it needs.
- Use
--no-custom-instructionswhen operating on untrusted repositories, or review repository instruction files before allowing them to influence Copilot. - Avoid
--silentfor security-sensitive operations; retain visible command and approval logs. - Run the CLI in a sandbox or container under a low-privilege account with minimal mounted files and no unnecessary credentials.
- Document the risks of prompt injection and require human review before executing generated commands or accepting security-sensitive file changes.
- Remove
