T05 · Unauthorized Access and Privilege Escalation
- Location
references/agent-usage.md:9- Finding
Unbounded Autonomous Agent Execution with Permission Checks Disabled
- Content
View full analysis
Vulnerability Details
File Location:
references/agent-usage.md, lines 9–12
Vulnerability Type: Permission bypass and unsafe unbounded automation
Risk Level: HighVulnerable Code:
bash while :; do claude --print --dangerously-skip-permissions \ "Read prd.json, find first story where passes=false, implement it, run checks, update passes=true if successful" doneTechnical Analysis
The documented workflow combines an unconditional infinite shell loop (
while :) with the--dangerously-skip-permissionsoption. This suppresses normal interactive authorization boundaries while directing an autonomous coding agent to read repository-controlled content, modify code, run quality checks, and update files.Although the agent prompt defines work through
prd.json, the workflow does not validate that file or constrain which commands may be executed during implementation and verification. Repository-controlled PRD entries, instruction files, source files, build scripts, test commands, or dependencies could therefore influence the agent's actions while approval checks are disabled.The loop also fails to evaluate the documented completion condition. Even after all stories have
passes: true, the shell continues launching new agent sessions. This can repeatedly consume CPU, API quota, and other resources, and may cause repeated or unintended repository operations.The effective privileges are limited by the operating-system account, environment, credentials, network access, and tools available to the Claude CLI process. However, within those boundaries, the workflow intentionally removes the agent's normal permission prompts and therefore violates least-privilege principles.
Attack Path
- A user follows the documented instructions and starts the unattended loop.
- The Claude CLI runs with
--dangerously-skip-permissions, removing interactive approval requirements. - The agent reads `p ...[truncated 1457 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
--dangerously-skip-permissionsand retain interactive approval for command execution, file access outside the repository, network operations, credential access, and destructive changes. - Replace
while :with a bounded loop that checks whether any incomplete stories remain before invoking the agent and exits immediately when all stories pass. - Set a maximum iteration count, execution timeout, retry limit, and API-cost budget.
- Validate
prd.jsonagainst a strict schema, including approved branch-name syntax, bounded story counts, expected field types, and rejection of command-like or instruction-injection content where possible. - Treat all repository content as untrusted data. Explicitly instruct the execution agent not to follow repository instructions that expand scope, disable safeguards, access secrets, or override the initiating user's requirements.
- Run unattended agents inside an isolated container or restricted worktree under a dedicated low-privilege account. Mount only required project paths and avoid exposing home directories, SSH keys, cloud credentials, tokens, or production configuration.
- Restrict network access and use an allowlist for required services. Provide short-lived, narrowly scoped credentials only when necessary.
- Allowlist quality-check commands rather than permitting arbitrary commands inferred from repository content.
- Require human review before commits, migrations, dependency installation, external publication, or other security-sensitive operations.
- Log every command and changed file, and stop execution immediately when unexpected paths, commands, or repeated failures are detected.
A safer control flow should first query for an incomplete story, invoke the agent only when one exists, preserve permission prompts, and terminate after a defined number of attempts.
- Remove
