T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/spawn-agent.sh:225- Finding
AI Coding Agent Runs with Approval and Sandbox Protections Disabled
- Content
View full analysis
"` # fails in tmux with "stdout is not a terminal". exec is the designed # one-shot entry point. # Use --dangerously-bypass-approvals-and-sandbox so codex can write to # the parent repo's .git/worktrees/ metadata (required for `git commit` # inside a worktree). Default workspace-write sandbox blocks ORIG_HEAD.lock. codex exec --model "$model" -c "model_reasoning_effort=$REASONING" --dangerously-bypass-approvals-and-sandbox "$PROMPT" ;; ``` ### Technical Analysis The `--dangerously-bypass-approvals-and-sandbox` option explicitly disables both command approval and filesystem sandbox protections. The resulting model-driven process inherits the invoking user's effective permissions rather than receiving access only to the selected project worktree and necessary Git metadata. The prompt can include operator-supplied task text, repository-derived content, and later instructions derived from work logs. Repository files may contain prompt-injection content. Because the agent can autonomously interpret that content and invoke tools without approval, untrusted repository instructions can cause access to files and commands unrelated to the coding task. The stated need to update Git worktree metadata does not justify unrestricted access to the user's home directory, provider credentials, SSH configuration, unrelated repositories, notification configuration, or arbitrary network-capable commands. ### Attack Path 1. An operator starts a task against a repository containing malicious instructions in source code, documentation, issue text, or generated files. 2. `spawn-agent.sh` incorporates the task prompt and directs Codex to inspect and modify ...[truncated 1259 chars]- Remediation
View remediation
` metadata exposed as writable. - The rest of the repository and host mounted read-only or not mounted. - No access to SSH agents, cloud credentials, browser profiles, or unrelated home-directory files. 3. Require explicit operator approval for: - Access outside the project. - Network clients other than the selected model provider. - Package installation and lifecycle scripts. - Git pushes, PR creation, and writes to protected branches. 4. Use a dedicated low-privilege service account with isolated provider credentials. 5. Apply outbound network allowlisting and prevent arbitrary destinations. 6. Treat repository text as untrusted data and tell agents not to follow instructions found in repository content unless they are relevant to the endorsed task. 7. If worktree metadata remains incompatible with the default sandbox, create a narrow helper for required Git operations rather than disabling the entire sandbox. ]]>
