T05 · Unauthorized Access and Privilege Escalation
- Location
askhuman/SKILL.md:13- Finding
Overly Broad Local Tool Permissions
- Content
View full analysis
Vulnerability Details
File Location:
askhuman/SKILL.md:13
Vulnerability Type: Excessive execution and file-read permissions
Risk Level: MediumVulnerable Code
yaml allowed-tools: Bash(curl *) Bash(node *) ReadTechnical Analysis
The Skill grants unrestricted access to
Bash(node *)and the general-purposeReadtool. Its documented workflow primarily requires HTTPS requests to the AskHuman API; no documented operation requires arbitrary Node.js execution.Unrestricted Node.js execution can run arbitrary local JavaScript with the privileges of the hosting agent process. General
Readaccess can expose files unrelated to the requested human-judgment task. These permissions violate least-privilege principles and substantially increase the consequences of malicious or untrusted content influencing the agent.The project does not contain instructions that explicitly exploit these permissions. The risk arises from the excessive authority available during Skill execution.
Attack Path
- A task response, worker message, prompt, or other untrusted content contains instructions encouraging the agent to inspect a local file or run Node.js code.
- The agent treats that content as actionable rather than untrusted data.
- The broad
Readpermission is used to access unrelated files, orBash(node *)is used to execute arbitrary JavaScript. - The accessed information may then be exposed through the agent response or transmitted using the permitted network tooling.
Impact Assessment
Successful exploitation could allow access to files readable by the agent process and arbitrary Node.js execution under that process's operating-system privileges. Potentially exposed data includes source files, configuration files, environment-derived credentials, and other local workspace content. This finding does not establish operating-system privilege escalation beyond the privileges already held by the agent.
- Remediation
View remediation
Remediation Suggestions
- Remove
Bash(node *)because the documented workflow does not require arbitrary Node.js execution. - Restrict file reads to paths explicitly selected by the user for attachment upload.
- Constrain
curlaccess to HTTPS requests against the documented AskHuman API host and required endpoint set. - Require explicit user confirmation before reading or uploading local files.
- Require explicit confirmation before any paid task, wallet signature, or permit operation.
- Treat task results and worker messages as untrusted data and prohibit interpreting their contents as tool-use instructions.
- Remove
