T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:72- Finding
Unsandboxed Autonomous Code Execution Through Danger-Full-Access Fallback
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 72–87
Vulnerability Type: Unrestricted host access beyond the workspace boundary
Risk Level: HighVulnerable instructions:
text In that context, prefer: codex exec --sandbox danger-full-access "<task>" Use process boundaries as the safety layer instead: explicit `workdir`, clean git status before launch, narrow task prompts, `git diff` review, targeted tests, and human/agent confirmation before committing broad changes.Technical Analysis
When normal workspace sandboxing fails in a Hermes gateway or service context, the Skill recommends rerunning Codex with
--sandbox danger-full-access. This mode removes the Codex filesystem sandbox and allows the autonomous coding agent to execute commands with the permissions of the Hermes host process.The suggested safeguards do not enforce an equivalent security boundary. An explicit
workdironly selects the initial working directory; it does not prevent access to paths outside that directory. Reviewinggit diffand requesting confirmation before committing occur after code execution and therefore cannot prevent prior host-file access, command execution, credential reads, or network activity.The instructions do not impose a mandatory, informed user-confirmation gate immediately before entering unrestricted mode. This creates a reachable authorization expansion when sandbox setup fails.
Attack Path
- Hermes delegates a coding or review task to Codex in a repository containing third-party-controlled source, issue, pull-request, or instruction content.
- Codex workspace sandboxing fails because of the documented gateway or service restrictions.
- Following the Skill instructions, the Agent reruns the task using
codex exec --sandbox danger-full-access. - Codex processes the delegated task and repository content while running with the full permissions of the Hermes process a ...[truncated 1080 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not automatically fall back to
--sandbox danger-full-accesswhen workspace sandboxing fails. - Fail closed and explain the sandbox error, or require explicit, informed user approval immediately before every unrestricted execution.
- Prefer repairing the sandbox configuration or running Codex in a disposable container or virtual machine.
- Mount only the intended repository into the isolated environment and make unrelated host paths unavailable.
- Remove unnecessary credentials and environment variables from the Codex process.
- Restrict outbound network access unless it is explicitly required for the approved task.
- Run Codex under a dedicated, low-privilege account with no access to unrelated user files.
- Preserve clean-status checks, narrow prompts, targeted tests, and diff review as defense-in-depth measures, but do not treat them as substitutes for runtime isolation.
- Do not automatically fall back to
