T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:887- Finding
Claude Code Permission Enforcement Is Explicitly Disabled
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 887-891
Vulnerability Type: Permission bypass and excessive agent privileges
Risk Level: HighVulnerable Code
bash alias cc='claude --dangerously-skip-permissions'Technical Analysis
The Skill requires the
cccommand to invoke Claude Code with the--dangerously-skip-permissionsoption. The documented workflows subsequently launchccinside project directories and authorize development agents to generate files, modify source code, execute tests, and create Git commits.This option deliberately disables Claude Code's normal interactive permission controls. It removes a security boundary intended to let users review sensitive operations such as executing shell commands or accessing files outside the immediate task scope.
Although the Skill's legitimate function requires project automation, globally disabling permission enforcement is broader than necessary. The resulting execution environment implicitly trusts instructions received from project files, agent output, and the externally integrated Orchestrix workflow.
Attack Path
- A user runs the documented workflow in a repository containing malicious or compromised instructions.
- The workflow starts
cc, which resolves toclaude --dangerously-skip-permissions. - Claude Code or an activated agent processes attacker-controlled repository content.
- That content induces a sensitive tool action, such as running an arbitrary command or reading or changing files beyond those required by the development task.
- Because permission enforcement is disabled, the action can execute without an informed user confirmation.
- The action runs with the operating-system privileges of the user who launched Claude Code.
Impact Assessment
Successful exploitation can provide access equivalent to the local account running the Skill. Depending on that account's permissions and Claude ...[truncated 689 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the unsafe alias and invoke Claude Code with normal permission enforcement:
bash alias cc='claude' - Define a narrow allowlist for the specific tools, commands, and project paths required by each workflow stage.
- Require explicit user confirmation for shell execution, access outside the selected project, credential access, destructive file operations, network operations, and Git publication actions.
- Run development agents in an isolated container or restricted operating-system account with only the current repository mounted.
- Prevent agents from accessing SSH keys, cloud credentials, browser profiles, environment-secret stores, and unrelated home-directory content.
- Separate document-generation privileges from code-execution privileges so planning agents cannot execute development commands unnecessarily.
- Record approved operations in an audit log and fail closed when an operation does not match the configured policy.
- Remove the unsafe alias and invoke Claude Code with normal permission enforcement:
