T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:23- Finding
Overbroad Forced Termination of Existing Chrome Processes
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12, 23, and 35
Vulnerability Type: Violation of least privilege through destructive process termination
Risk Level: MediumVulnerable Code
markdown 1. **Kill all Chrome processes**powershell # Step 1: Kill Chrome taskkill /F /IM chrome.exe /T 2>$null Start-Sleep -Seconds 2bash # Step 1: Kill Chrome pkill -f "Google Chrome" 2>/dev/null; sleep 2Technical Analysis
The Skill instructs the agent to forcibly terminate every matching Chrome process before opening the requested browser instances. This is broader than necessary for launching an ordinary browser and a separate debugging browser.
On Windows,
/Fforcibly terminates allchrome.exeprocesses, while/Talso terminates their child processes. On macOS,pkill -f "Google Chrome"terminates processes based on a broad command-line match. Neither command limits termination to processes previously created by the Skill.Consequently, the action crosses the task's legitimate process-control boundary and can affect unrelated browser sessions owned by the current user.
Attack Path
- A user submits a phrase that activates the Chrome Debug Launcher Skill.
- The agent follows the mandatory first step before launching either requested instance.
- The Windows or macOS termination command identifies every matching Chrome process.
- Existing interactive sessions, downloads, browser automation jobs, and child processes are forcibly terminated.
- Only after this disruption does the Skill launch the two new browser instances.
No elevated privilege acquisition is demonstrated. The affected scope is generally limited to Chrome processes the executing user is authorized to terminate.
Impact Assessment
Successful execution can:
- Terminate unrelated Chrome sessions belonging to the current user.
- Discard unsaved form input or other transie ...[truncated 425 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to kill all Chrome processes.
- Launch each Chrome instance with a distinct
--user-data-dirso that existing sessions do not need to be terminated. - Track the process identifiers of browser instances created by the Skill and terminate only those processes during cleanup.
- If termination of an existing browser is unavoidable, enumerate the exact target processes and obtain explicit user confirmation before stopping them.
- Avoid broad process-name or command-line matching such as
taskkill /IM chrome.exeandpkill -f. - Implement graceful shutdown before forced termination and reserve forced termination for confirmed, Skill-owned processes that fail to exit.
