T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:38- Finding
Automatic Root Escalation for Android Device-Control Operations
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:9-13, 38-41, 50-54, 62-63, 71-72, 80-81, 89-90
Vulnerability Type: Automatic privilege escalation without per-operation authorization
Risk Level: HighThe skill automatically retries routine Android device-control operations through
su -cwhenever their non-root equivalents fail. This behavior applies to UI hierarchy extraction, screenshot capture, touch and swipe injection, application launching, and text input.Complete vulnerable code snippets:
bash # Try non-root uiautomator dump /sdcard/ui_dump.xml 2>/dev/null \ && cat /sdcard/ui_dump.xml \ || ( # Fallback to root su -c "uiautomator dump /sdcard/ui_dump.xml" && su -c "cat /sdcard/ui_dump.xml" )bash TMP="/sdcard/ai_screen.png" # Try non-root screencap -p "$TMP" 2>/dev/null \ && base64 "$TMP" \ || ( # Root fallback su -c "screencap -p $TMP" su -c "base64 $TMP" )bash input tap 540 1600 2>/dev/null \ || su -c "input tap 540 1600"bash input swipe 500 1600 500 600 300 2>/dev/null \ || su -c "input swipe 500 1600 500 600 300"bash am start -n com.android.settings/.Settings 2>/dev/null \ || su -c "am start -n com.android.settings/.Settings"bash input text "Hello" 2>/dev/null \ || su -c "input text 'Hello'"Technical Analysis
The shell
||operator invokes the root command after any non-zero exit status from the ordinary command. The logic does not distinguish an authorization failure from transient errors, invalid arguments, missing files, unavailable services, or partial command failure. Consequently, an ordinary operational error becomes an implicit request for elevated execution.No explicit per-operation approval, privilege policy, action allowlist, or validation step is required before
su -cis invoked. Redirect ...[truncated 1916 chars]- Remediation
View remediation
Remediation Suggestions
- Remove automatic
su -cfallback from all routine operations. - Return the original non-root error to the caller instead of suppressing it with
2>/dev/null. - If elevation is genuinely necessary, require explicit and informed approval for each elevated operation. The approval prompt should identify the exact command, arguments, reason for elevation, and expected effect.
- Separate non-root and root workflows so selecting ordinary device control can never silently transition into elevated execution.
- Apply strict allowlists for executable names, application components, file paths, coordinates, and supported argument formats.
- Avoid shell-string construction for elevated commands. Where possible, invoke fixed commands with structured arguments to reduce command-injection risk when examples are adapted to dynamic input.
- Restrict elevated screenshot and UI-dump output to securely created files, apply restrictive permissions, and delete temporary artifacts immediately after use.
- Add audit logging for every requested and approved elevated action, including the initiating task, command, result, and timestamp.
- Document which operations require elevated access and deny elevation for actions that can be completed through standard Android APIs or explicitly granted non-root permissions.
- Remove automatic
