T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:17- Finding
Unnecessary Filesystem Capabilities Violate Least-Privilege Principles
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:17-20
Vulnerability Type: Excessive tool permissions
Risk Level: MediumVulnerable Configuration
yaml tools: - read_file - write_fileTechnical Analysis
The Skill is designed to draft and review patient-facing text, but it requests both
read_fileandwrite_file. No documented workflow inSKILL.mdrequires reading from or writing to the local filesystem.In particular,
write_filegrants an integrity-affecting capability beyond the Skill's legitimate text-generation purpose. If untrusted patient-message content, imported text, or later prompt injection influences the agent, this unnecessary capability could be invoked to modify files accessible under the host's tool policy.The precise filesystem privileges depend on runtime sandboxing and authorization controls; the configuration does not itself establish unrestricted filesystem access. Nevertheless, requesting an unused write capability unnecessarily increases the impact of agent manipulation.
Attack Path
- An operator supplies an untrusted message or document for HIPAA review.
- The content contains instructions intended to manipulate the agent into performing an unrelated file operation.
- Because the Skill declares
write_file, the agent may attempt to follow those instructions using that capability. - If runtime policy permits the target path, an accessible file may be created, overwritten, or poisoned.
- Modified configuration, documentation, or other agent-consumed data could subsequently affect project integrity or later sessions.
Impact Assessment
Successful exploitation could provide unauthorized modification of files within the runtime identity's writable scope. Possible consequences include loss of data integrity, corruption of project files, or poisoning of content later consumed by an agent or user.
This finding does not demonstrate operating- ...[truncated 158 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove both filesystem tools when the Skill only needs to return generated text:
yaml tools: [] -
If file-based input is genuinely required, retain only
read_fileand restrict it to an explicitly approved workspace. -
If output persistence is required, constrain
write_fileto a dedicated output directory. -
Require explicit user confirmation before creating or overwriting a file.
-
Prohibit overwriting existing files by default and use collision-resistant output names.
-
Ensure the host runtime applies path canonicalization, blocks traversal, and denies access outside the approved directory.
-
Treat all patient-supplied or imported content as untrusted data rather than executable agent instructions.
-
