T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:346- Finding
AI backends run with permission checks and sandbox protections disabled by default
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 346–347
Vulnerability Type: Default permission-prompt and sandbox bypass
Risk Level: HighVulnerable snippet:
markdown | `CODEAGENT_SKIP_PERMISSIONS` | Skip Claude backend permission prompts (`true`/`false`) | true | | `CODEX_BYPASS_SANDBOX` | Control Codex sandbox bypass (`true`/`false`) | true |Technical Analysis
The documented defaults set both
CODEAGENT_SKIP_PERMISSIONSandCODEX_BYPASS_SANDBOXtotrue. Consequently, the Skill's standard invocation patterns can delegate tasks to AI coding backends without interactive permission approval and without the Codex sandbox boundary unless callers explicitly override these settings.Backend actions may be influenced by task text, repository content, agent presets, and automatically injected skills. Disabling both safeguards allows such content to influence tool execution with the filesystem and process privileges of the account running
codeagent-wrapper, rather than restricting operations to the intended project or isolated worktree.The available project contains only the Skill documentation and does not include the wrapper implementation. The finding is therefore based on the effective operational defaults explicitly prescribed by
SKILL.md; it does not establish that the wrapper itself contains malicious code.Attack Path
- A user invokes
codeagent-wrapperaccording to the documented standard patterns without overriding the two environment-variable defaults. - The wrapper delegates a task to the Claude or Codex backend while processing task text, repository files, an agent preset, or an injected skill.
- Untrusted or unsafe instructions in that content induce the backend to request a sensitive tool action, such as executing a shell command or accessing a path outside the selected project.
- For Claude, the permission prompt is skipped by default; for Codex, the sandbox is bypassed by default.
- The r ...[truncated 811 chars]
- A user invokes
- Remediation
View remediation
Remediation Suggestions
- Change both defaults to
false:CODEAGENT_SKIP_PERMISSIONS=falseCODEX_BYPASS_SANDBOX=false
- Require explicit, per-task user authorization before enabling either bypass.
- Reject bypass activation through repository-controlled content, injected skills, or agent-generated parameters.
- Enforce a wrapper-level filesystem boundary around the selected work directory or isolated worktree rather than relying solely on backend controls.
- Apply least-privilege tool allowlists and deny access to unrelated credential stores, home-directory configuration, and system paths.
- Record bypass activation in structured audit logs, including the task, backend, requesting user, and authorized scope.
- For high-risk operations, retain an independent confirmation gate even when a backend-specific permission mechanism is disabled.
- Change both defaults to
