T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:499- Finding
Sandbox Bypass Instruction Enables Unrestricted Filesystem Operations
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:499
Vulnerability Type: Sandbox bypass and privilege expansion
Risk Level: HighSource Snippet:
markdown - On Windows, moving files into the Documents directory may trigger sandbox blocking and require `dangerouslyDisableSandbox`.Technical Analysis
The Skill explicitly recommends disabling the execution sandbox when filesystem operations are blocked. A sandbox is a security boundary intended to constrain the Agent to approved files and directories. Disabling it grants substantially broader access than document conversion legitimately requires.
This instruction is particularly dangerous in combination with the initialization workflow, which relocates files recursively from a user-selected directory. The Skill does not require canonical path validation, a narrowly scoped permission grant, or verification that the selected directory is dedicated exclusively to the knowledge base.
Attack Path
- A user invokes initialization or update against a directory under the Windows Documents hierarchy.
- The Skill attempts to move source files into the
raw/directory. - The sandbox blocks access outside the permitted workspace.
- Following the Skill instructions, the Agent reruns the operation with
dangerouslyDisableSandbox. - The Agent can then read, move, overwrite, or otherwise affect files beyond the original sandbox boundary.
- A mistaken path, malicious document workflow, or compromised dependency can abuse the expanded access to affect unrelated user data.
Impact Assessment
Exploitation can provide the Agent or code running through it with access to files outside the approved workspace. The effective scope is determined by the operating-system privileges of the Agent process and may include the user's Documents directory and other user-accessible locations.
Potential consequences include unauthorized file disclosure, relocatio ...[truncated 222 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove every instruction recommending
dangerouslyDisableSandboxor equivalent sandbox bypasses. - Require the knowledge-base root to reside inside an explicitly approved workspace.
- Resolve and canonicalize every path before use, then verify that it remains below the approved root.
- Request narrowly scoped access to the specific source and destination directories rather than disabling the entire sandbox.
- Stop safely and explain the required permission if an operation is blocked.
- Add protection against symlink, junction, and path-traversal escapes.
- Generate a reviewed file-operation manifest before moving data.
- Implement rollback or recovery support for partially completed file operations.
- Remove every instruction recommending
