T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:13- Finding
Read-Only Validation Scope Contradicted by Unauthorized Artifact Modification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 13 and 75–76
Vulnerability Type: Scope violation and unauthorized artifact modification
Risk Level: MediumVulnerable Instructions
markdown This is **not** a code review skill. It is a read-only release gate that determines whether an artifact is ready to move forward. QA Gate inspects artifacts but does not modify them.markdown ### Step 4: If FAIL, fix and re-validate Fix all CRITICAL and MAJOR issues. Re-run the gate. Only present to principal after PASS or PASS WITH FIXES.Technical Analysis
The Skill explicitly establishes a read-only security boundary at line 13, telling users that it inspects artifacts without modifying them. Lines 75–76 contradict that boundary by directing the Agent to fix every issue classified as CRITICAL or MAJOR.
This instruction grants modification authority without requiring separate user consent, validating the target path, preserving a backup, generating an approval-only patch, or limiting the nature and extent of changes. Because QA classification involves model judgment, a false positive or incorrect proposed correction can cause the Agent to alter otherwise valid source code, configuration, documentation, or other reviewed artifacts.
This is classified as
T05: Unauthorized Access and Privilege Escalationbecause the Skill expands its operational privileges from the declared inspection-only role to write access over the artifact.Attack Path
- A user invokes the Skill based on its stated read-only behavior.
- The Agent reads an artifact and performs the six prescribed validation checks.
- The Agent, correctly or incorrectly, classifies a finding as CRITICAL or MAJOR.
- Step 4 directs the Agent to modify the artifact rather than merely report or propose the correction.
- The Agent writes changes without obtaining explicit authorization for that write operation.
- The Agent ...[truncated 1218 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace the automatic remediation instruction with a report-only workflow. For example:
markdown ### Step 4: If FAIL, propose fixes and request approval Describe proposed corrections for all CRITICAL and MAJOR findings. Do not modify the artifact unless the user explicitly authorizes the changes. -
Require explicit, separate user confirmation before performing any write operation.
-
Present proposed changes as a patch or diff so the user can review the exact modifications before application.
-
Restrict approved changes to the explicitly selected artifact and reject path expansion, unrelated file edits, or modifications outside the workspace.
-
Preserve the original artifact or ensure that changes are recoverable through version control or a backup.
-
After approved remediation, report every changed file and re-run validation against the modified version.
-
Clarify whether report generation under
qa-gate/is the sole write operation permitted during normal read-only validation.
-
