T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:8- Finding
Excessive Agent Tool Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:8
Vulnerability Type: Excessive permissions that violate the principle of least privilege
Risk Level: Mediumyaml allowed-tools: [Bash, Read, Write, Exec, WebSearch]Technical Analysis
The Skill grants general-purpose shell execution, process execution, filesystem reading, and filesystem writing through
Bash,Exec,Read, andWrite. Its documented investment-research workflow primarily requires market-data retrieval, analysis, and report formatting. No documented workflow step establishes a legitimate need for unrestricted command execution or general filesystem access.This broad tool configuration increases the impact of untrusted instructions originating from user input, externally retrieved market data, or delegated Skills. If such content causes the Agent to invoke these tools, it could execute commands or access local files beyond the scope of the investment-analysis task.
The reviewed project does not contain a malicious command or direct instruction to abuse these permissions. Exploitation therefore depends on hostile or compromised content reaching the Agent while the excessive tools are available.
Attack Path
- The investment Skill is loaded with
Bash,Exec,Read, andWriteenabled. - The workflow processes user-controlled input, externally sourced market information, or output from a delegated Skill.
- Malicious content embedded in one of those inputs instructs the Agent to invoke an unnecessarily authorized tool.
- If the Agent follows that instruction,
Readcould expose accessible local files,Writecould alter accessible files, andBashorExeccould run commands with the privileges of the hosting Agent process. - The resulting activity could extend beyond investment research into unauthorized local-system access.
Impact Assessment
Successful exploitation could provide access to any files and co ...[truncated 492 chars]
- The investment Skill is loaded with
- Remediation
View remediation
Remediation Suggestions
- Remove
Bash,Exec,Read, andWritefromallowed-toolsunless each capability is supported by a specific, documented workflow requirement. - Prefer narrowly scoped market-data interfaces such as the declared
data_layerormcp-aktoolsoperations rather than general-purpose shell execution. - If report persistence is required, replace unrestricted
Writeaccess with a constrained output capability limited to a dedicated report directory, approved file types, and non-overwriting filenames. - If local file reads are required, restrict them to explicit Skill resources or an allowlisted data directory.
- If command execution is unavoidable, use fixed commands with validated arguments, deny shell metacharacters, run inside a sandbox, and apply operating-system resource and network restrictions.
- Treat user input, web results, market data, and delegated-Skill output as untrusted content. Do not allow instructions embedded in that content to authorize tool use.
- Add tests confirming that the workflow completes using only the minimum required tools and that unauthorized filesystem paths and commands are rejected.
- Remove
