T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:34- Finding
Overly Broad Tool Permissions Violate Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 34–44
Vulnerability Type: Excessive tool authorization
Risk Level: MediumVulnerable Configuration
yaml allowed-tools: - Read - Write - Edit - Grep - Glob - Bash - AskUserQuestion - WebFetch - WebSearch - AgentTechnical Analysis
The Skill is intended to plan, draft, review, and polish technical articles. Most of this workflow requires document access, user interaction, and optional web research. However, the configuration also grants unrestricted shell execution through
Bashand general-purpose delegation throughAgent.These capabilities exceed the minimum privileges required for the declared writing workflow. The filesystem tools are also not explicitly limited to user-approved source files, generated drafts, or a designated output directory.
No malicious shell command or deliberate abuse of these permissions was found in the reviewed files. The risk arises from the unnecessarily broad authorization boundary: attacker-controlled article material, untrusted web content, or a compromised delegated agent could influence the model into using these tools for actions unrelated to article production.
Attack Path
- A user invokes the Skill with attacker-controlled source material or requests optional online research.
- The Skill reads the material or retrieves untrusted web content.
- The untrusted content contains instructions designed to redirect tool use.
- Because the Skill is authorized to invoke
Bash, access the filesystem, and delegate toAgent, the influenced agent attempts actions outside the writing task. - Depending on host-level sandboxing and approval controls, those actions could read unrelated files, alter local content, execute commands, or initiate further delegated operations.
This is a capability-based exploitation path. The audited files do not contain a built-in ...[truncated 860 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
Bashbecause the documented article-writing workflow does not establish a legitimate need for arbitrary shell execution. - Remove
Agentunless delegation is essential and its permitted tasks can be narrowly defined. - Restrict
Read,Write, andEditoperations to:- Files explicitly selected by the user.
- A dedicated workspace for generated drafts.
- A user-confirmed final output path.
- Make
WebFetchandWebSearchopt-in for the research phase rather than available throughout every execution mode. - Treat fetched pages, article drafts, and reference material as untrusted data. Explicitly instruct the agent never to follow tool-use instructions found inside that content.
- Require user confirmation before overwriting files, accessing paths outside the workspace, or invoking delegated workflows.
- Apply runtime controls independently of Skill instructions, including filesystem sandboxing, command allowlists, network restrictions, and sensitive tool-call approval.
- Define separate tool sets for each mode. For example, outline-only mode should not receive write, edit, shell, or delegation privileges.
- Remove
