T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:25- Finding
Excessive Tool Permissions Violate Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 25–32
Vulnerability Type: Excessive tool authorization
Risk Level: Mediumyaml allowed-tools: - Read - Write - Edit - Grep - Glob - Bash - AskUserQuestion - WebFetch - AgentTechnical Analysis
The skill authorizes
Bash,WebFetch, andAgent, although its documented workflows only require local project inspection, README assessment, report generation, and controlled Markdown editing. No defined workflow requires arbitrary command execution, network retrieval, or delegation to another agent.This violates the principle of least privilege. Because the skill processes potentially attacker-controlled repository content, an indirect prompt-injection attempt or erroneous generated instruction could try to use these unnecessary capabilities.
WriteandEditare also unnecessary in audit mode, which is explicitly documented as read-only.No evidence was found that the skill currently invokes these tools maliciously. The risk arises from the overly broad capability boundary.
Attack Path
- A user invokes the skill against an untrusted project.
- The skill reads attacker-controlled README, source, metadata, or documentation content.
- That content contains instructions crafted to influence the executing agent.
- The agent interprets those instructions as actionable despite their untrusted origin.
- The unnecessarily authorized
Bash,WebFetch, orAgentcapability is used to execute commands, communicate externally, or delegate a privileged operation. - Depending on the host’s sandbox and authorization model, this may affect files or data accessible to the agent.
This path requires a separate influence mechanism, such as indirect prompt injection; the audited project does not itself contain a confirmed exploit payload.
Impact Assessment
Successful exploitation could permit:
- Execution of shell commands with the privileges of the host agen ...[truncated 504 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
Bash,WebFetch, andAgentfrom the defaultallowed-toolslist. - Use a read-only tool profile for audit mode, limited to
Read,Grep, andGlob. - Enable
WriteandEditonly for create mode or after explicit user confirmation in rewrite mode. - If shell execution later becomes essential, expose narrowly scoped commands through validated wrappers rather than unrestricted
Bash. - If external retrieval later becomes necessary, restrict destinations with an allowlist, reject private and link-local addresses, and require confirmation before transmitting project data.
- Treat all repository content as untrusted data and explicitly instruct the agent not to follow instructions embedded in inspected files.
- Add tests verifying that audit mode cannot modify files, execute commands, access the network, or delegate tasks.
- Remove
