T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:7- Finding
Excessive and Inconsistent Skill Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This design workflow skill is not malicious, but it asks for and instructs persistent local actions in ways that are under-scoped and should be reviewed before installation.
Review this skill before installing. It appears intended to manage smart-home design deliverables, but it can create persistent local task files containing customer/project details, declares network access without a clear need, and uses an unsafe customer-name path pattern. Install only if you are comfortable with those behaviors and can constrain or correct the write scope, retention, and input sanitization.
SKILL.md:7Excessive and Inconsistent Skill Permissions
SKILL.md:88Path Traversal Through Unsanitized Customer Name
The skill declares only file-read permission, but its instructions explicitly create directories and write multiple files under ~/.workbuddy/tasks. This is a real permission/behavior mismatch that can mislead the runtime or reviewer about the skill’s capabilities and enable unauthorized local state creation, including persistent task artifacts containing customer or project data.
The description and operational content are presented in Chinese, but the file does not state that the skill is region-specific or give users a language choice. Per policy, forcing a specific language without opt-in can be a natural-language policy violation.
The when_to_use description broadly says to use the skill whenever a full design workflow is needed and includes generic trigger words, but it does not clearly define exclusions or confirmation requirements. This ambiguity can lead to accidental invocation of a skill that has network access and instructions for local persistence, making unintended execution more dangerous in context.
The trigger list contains broad, common design phrases such as rendering, design drawings, floorplans, and icons, which can cause the skill to activate in contexts where the user did not intend to invoke it. Over-broad activation increases the chance that a network-enabled skill with operational instructions is engaged on unrelated requests, expanding the attack surface and risking unintended data handling.
This duplicated finding points to the same session-persistence behavior: the skill writes multiple workflow files into a durable user directory. In the context of a design workflow that may process customer floorplans, device inventories, and delivery progress, persistence meaningfully raises the risk of leaking sensitive project metadata across sessions or to other tools.
TASK_NAME="design-${CUSTOMER}-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
# 任务计划 - 设计交付
This duplicated finding points to the same session-persistence behavior: the skill writes multiple workflow files into a durable user directory. In the context of a design workflow that may process customer floorplans, device inventories, and delivery progress, persistence meaningfully raises the risk of leaking sensitive project metadata across sessions or to other tools.
TASK_NAME="design-${CUSTOMER}-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
# 任务计划 - 设计交付
No suspicious patterns detected.