T05 · Unauthorized Access and Privilege Escalation
- Location
references/recorrido-navegador.md:15- Finding
Audit instructions permit unapproved creation of an unauthenticated preview route
- Content
View full analysis
Vulnerability Details
File Location:
references/recorrido-navegador.md:15-20
Vulnerability Type: Unauthorized source modification and access-control weakening
Risk Level: MediumVulnerable Instruction
markdown 2. **¿Necesita variables de entorno?** Si faltan y la app no arranca, no inventes: audita el código y anota en "No verificado" que el recorrido no se pudo hacer y por qué. 3. **Si la app exige login y no lo tienes**, busca (o crea, si es barato) una ruta de previsualización que renderice el shell con datos falsos. En una de las apps de origen existía una ruta así y es lo que permitió medir el menú móvil sin sesión. Es la forma honesta de auditar el layout sin credenciales.Technical Analysis
When an application requires authentication and the auditor lacks credentials, the instructions authorize the agent to create a preview route based only on whether doing so is “cheap.” This is an instruction to modify the audited repository during the audit phase.
That behavior conflicts with the Skill’s own approval boundary in
SKILL.md, which requires the agent to stop after producing the report and wait for approval before editing files. The preview-route instruction contains no equivalent approval requirement, local-only restriction, production-build exclusion, or technical control preventing the route from accessing real application services.Although the stated purpose is legitimate UX inspection using synthetic data, the instruction creates a reachable path for an agent to make an access-control-sensitive source change without the repository owner’s explicit approval. There is no evidence that the Skill author intends to create a backdoor, so this is classified as suspicious rather than malicious.
Attack Path
- A user requests a UX audit of a repository containing an authenticated application.
- The user does not provide test credentials.
- The agent follows
references/recorrido-navegador.md:18-20. - I ...[truncated 1266 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to create a preview route during the audit phase.
- If no existing preview route or test credentials are available, require the agent to record the authenticated browser flow as “Not verified.”
- Permit creation of a preview mechanism only after explicit user approval at the Phase 4 checkpoint.
- Require any approved preview mechanism to:
- Bind only to the local development environment.
- Be excluded from production builds.
- Use synthetic data exclusively.
- Avoid production databases, sessions, APIs, and secrets.
- Fail closed when the environment is not explicitly marked as development or test.
- Require the agent to list every modified file and remove the preview mechanism after testing unless the user expressly requests that it remain.
- Add an explicit instruction such as:
markdown Do not create or modify routes during the audit. If no existing safe preview route or test account is available, mark authenticated browser coverage as “Not verified.” A local-only preview route may be created only after the user explicitly approves the application plan.
