T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/evaluate-execution-mode.js:7- Finding
Undocumented Access to Shared Operational Configuration, Database Statistics, and Metrics
- Content
View full analysis
Vulnerability Details
File Location:
scripts/evaluate-execution-mode.js:7-12, 27-28, 76-95, 137-144;scripts/get-metrics.js:6-12
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: MediumThe skill documentation states that the package is a prompt-only orchestrator with no direct scripts. Nevertheless, the package contains executable scripts that cross the skill directory boundary and access shared application modules, configuration, environment-variable indicators, database statistics, and operational metrics.
Complete Code Snippets
From
scripts/evaluate-execution-mode.js:js const fs = require('fs'); const path = require('path'); const sharedDir = path.resolve(__dirname, '..', '..', '..', 'shared'); const config = require(path.join(sharedDir, 'config')); const { initDatabase, getDb } = require(path.join(sharedDir, 'database')); const { formatError } = require(path.join(sharedDir, 'errors'));js function count(sql) { return getDb().prepare(sql).get().count; }js { key: 'notification', status: process.env.TELEGRAM_BOT_TOKEN ? 'pass' : 'warn', zh: process.env.TELEGRAM_BOT_TOKEN ? '已配置 Telegram 通知通道。' : '未配置 Telegram 通知通道。', en: process.env.TELEGRAM_BOT_TOKEN ? 'Telegram notification channel is configured.' : 'Telegram notification channel is not configured.', actionZh: '确保策略执行失败、价格触发、风控事件均可即时通知。', actionEn: 'Ensure execution failures, alert triggers, and risk events notify users immediately.', }, { key: 'signer_control', status: process.env.EXECUTION_SIGNER_REF ? 'warn' : 'fail', zh: process.env.EXECUTION_SIGNER_REF ? '检测到执行签名器引用(需进一步审计权限边界)。' : '未检测到执行签名器控制面(HSM/MPC/KMS)。', en: process.env.EXECUTION_SIGNER_REF ? 'Execution signer reference detected (permission boundaries still need audit).' : 'No signer control-plane detected (HSM/MPC/KM ...[truncated 4213 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the operational assessment and metrics scripts from this prompt-only orchestration skill if they are not required for its documented purpose.
- If the functionality is legitimate, move it into a separately reviewed operations or readiness skill and explicitly document its data-access requirements.
- Replace direct database and environment access with a narrow, read-only service interface that returns only approved aggregate fields.
- Apply an explicit output allowlist to
getMetricsSummary()results and redact identifiers, secrets, internal endpoints, detailed error data, and tenant-specific information. - Avoid resolving and loading mutable modules outside the package boundary. Pin trusted modules through a defined package dependency or a controlled internal API.
- Run operational scripts under a dedicated least-privilege identity with read-only database permissions and restricted environment-variable visibility.
- Add authorization checks before exposing readiness or metrics output, and ensure standard output is not automatically included in user-facing agent responses.
- Update
SKILL.mdso the declared capabilities, executable scripts, required permissions, and expected outputs accurately match the shipped package. - Add automated tests that fail when unapproved fields are emitted or when scripts access files and modules outside their authorized directory boundary.
