T01 · Skill Instruction Hijacking
- Location
SKILL.md:67- Finding
Skill Instructions Require Execution Outside the Sandbox with Elevated Permissions
- Content
View full analysis
" cwd: ``` ### Technical Analysis The Skill explicitly instructs the Agent to obtain elevated permission and execute outside its sandbox. A visible browser may legitimately require narrowly scoped GUI access, but the instruction mandates a blanket sandbox escape rather than requesting only the minimum capabilities needed for Edge and network access. This changes the Agent's security posture when the Skill is loaded and breaks least-privilege boundaries. It also increases the impact of every other defect in the package, including unsafe file writes, attacker-controlled navigation, and dependency installation. ### Attack Path 1. A user activates the CNKI download Skill. 2. The Agent reads `SKILL.md` and treats its instructions as mandatory. 3. The Agent requests or obtains elevated, out-of-sandbox execution. 4. The Agent runs `npm install` and the bundled Node.js scripts with host-level access. 5. Any compromised dependency, malicious configuration, unsafe remote page, or future package update can act with the expanded host permissions. ### Impact Assessment Successful exploitation can provide the executed scripts or dependencies with access beyond the normal Agent sandbox. The precise scope depends on the host's approval mechanism and operating-system account, but it may include broader filesystem access, network access, GUI automation, persistent browser data, and modification of user-writable host files. No direct operating-system administrator escalation mechanism was f ...[truncated 143 chars]- Remediation
View remediation
