T05 · Unauthorized Access and Privilege Escalation
- Location
onescience-installer/SKILL.md:13- Finding
Mandatory Reading and Disclosure of the Entire SSH Configuration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed OneScience workflow helper, but it grants broad remote execution, SSH metadata access, cloud upload, and destructive install authority without enough scoping or confirmation.
Review before installing. Only use this skill in a dedicated workspace and with a clearly selected DCU host. Do not allow it to print your full SSH config, upload broad project directories, delete existing remote directories, or run unpinned install scripts unless you have independently reviewed the target host, file list, repository commit, and commands.
onescience-installer/SKILL.md:13Mandatory Reading and Disclosure of the Entire SSH Configuration
onescience-installer/SKILL.md:69Unpinned Remote Code and Dependencies Are Downloaded and Executed
onescience-installer/SKILL.md:80Recursive Deletion Uses an Unvalidated Relative Path
onescience-debug/references/e2e_pipeline_test.md:54Broad Project File Collection and Upload to an External SCnet Service
onescience-runtime/SKILL.md:82Untrusted Runtime Configuration Is Interpolated into Executable Shell Context
The workflow goes beyond testing and directs the agent to analyze failures, implement code fixes, and rerun tests. For a routing/management skill, this is a material privilege expansion: an attacker could leverage the testing flow to induce unauthorized source-code changes under the guise of 'repair', causing integrity loss or insertion of unsafe logic.
The document contains contradictory instructions: one section says not to modify the code under test, while another directs the agent to implement repairs. In practice, such conflicts create unsafe ambiguity that can be exploited to justify unauthorized code edits, especially when failures occur and the agent chooses the more permissive path.
The skill’s declared behavior is a remote installation and system administration workflow, which materially exceeds the parent skill’s stated role as a content/router manager for models, datasets, and components. This kind of capability expansion is dangerous because it can cause the agent to perform privileged actions on local and remote systems under a misleading trust boundary.
The skill mandates reading ~/.ssh/config from the user’s local machine, which exposes sensitive connection metadata such as host aliases, usernames, ports, and infrastructure layout. That access is not justified by the parent skill’s stated routing/content role, so it creates an unnecessary privacy and reconnaissance risk.
The skill instructs the agent to perform remote system administration over SSH, including environment modification, package installation, code retrieval, and validation on a remote host. This is a substantial privileged action set unrelated to the parent skill’s described orchestration purpose and could be abused to alter remote systems or deploy unreviewed software.
The instruction to run rm -rf on the remote onescience directory is destructive and provides no warning, backup step, or confirmation flow. If the path contains modified work, local patches, or valuable data, the action can cause irreversible data loss on the remote system.
Several routing categories use overlapping, underspecified keywords without clear scope boundaries, which makes misclassification likely. Because this manager orchestrates other skills rather than only answering textually, ambiguous matching can invoke the wrong capability chain and cause unintended code generation, runtime execution, or debugging against the wrong context.
The skill describes reading runtime configuration, generating SLURM scripts, and submitting training or data-processing jobs, but it does not require an explicit user-facing warning or confirmation about compute costs, cluster side effects, queue usage, or data exposure. In this context, the omission is materially risky because the skill is designed to bridge from natural-language requests into actual job execution on shared infrastructure.
The trigger keywords are broad enough that ordinary requests such as 'research', 'project', 'predict', or 'data' could activate workflows that generate code, prepare jobs, or route into runtime execution unintentionally. In this skill, that risk is amplified because routing can lead to downstream SLURM submission and other side-effecting operations, so ambiguous intent classification can escalate a harmless query into operational actions.
The environment installation flow includes reading SSH configuration, establishing a remote DCU connection, and installing dependencies, yet no explicit safety notice, trust boundary, or confirmation requirement is stated. This is dangerous because remote installation can modify external systems, consume privileged access, and create persistence or configuration drift if triggered from an ambiguous or manipulated prompt.
The skill is framed as analysis and planning, but its instructions explicitly extend into code generation, debugging orchestration, and file output. That broadens the skill from advisory behavior into acting on the environment, which can cause unintended code changes or persistence without clear user consent or scoped safeguards.
The skill mandates use of a separate debugging skill in a loop until tests pass, effectively creating delegated execution and iterative modification behavior. This is risky because it can trigger repeated external actions and code changes outside a pure planning role, increasing the chance of unsafe tool use, runaway loops, or unauthorized task execution.
The skill instructs that generated plans and code should be saved to the current case directory by default, but it does not require an explicit user warning or consent for filesystem writes. Implicit writes are dangerous because they create persistent side effects, may overwrite existing artifacts, and can be abused when the working directory contains sensitive or unexpected files.
This markdown file uses Chinese throughout the operational description, parameter explanations, and risk notes, and does not indicate that the user can choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless a locale-specific constraint is clearly justified.
This markdown file uses Chinese throughout its natural-language instructions and descriptions, with no indication that the user can choose another language or that the skill is intentionally region-specific. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.
This markdown file presents all operational instructions and constraints in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. That creates a natural-language policy concern because the file effectively forces a specific language without user opt-in.
This markdown file contains all substantive instructions and contract details in Chinese, with no indication that users may choose another language or that the Chinese-only format is required for a specific regional context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
This markdown file uses Chinese throughout its headings and content, which effectively forces a specific language for users reading the contract. The policy allows locale constraints only when user choice is offered or the constraint is clearly documented and justified, neither of which appears here.
This markdown file contains user-facing natural-language documentation entirely in Chinese, including headings and operational descriptions. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation, and this file does not indicate that Chinese is required or that alternate language support is available.
This markdown file contains user-facing documentation entirely in Chinese, including headings and operational descriptions, with no indication that the user can choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. That can violate language/locale policy because it effectively forces one language without opt-in.
This markdown file uses Chinese throughout its headings and operational descriptions, which can force a specific language on users or maintainers without opt-in. The policy permits locale constraints only when choice or clear justification is provided, neither of which appears here.
This markdown file contains user-facing natural-language content only in Chinese, including headings, parameter descriptions, and risk notes. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.
This markdown file contains its operational description exclusively in Chinese, including headings, parameter explanations, risks, and usage notes. Under the policy for natural-language violations, forcing a specific language without user opt-in or justification is a locale/language policy issue.
The file is written entirely in Chinese and states a naming convention as the current preferred standard, but it does not provide an opt-in language choice or explain why a Chinese-only convention is required. This can violate language/locale policy when users or contributors may reasonably expect language flexibility.
This markdown file presents all substantive operational guidance in Chinese, including headings, parameter descriptions, risks, and usage notes. Under the policy, forcing a specific language without user opt-in or a documented locale-specific justification is a natural-language policy violation.
No suspicious patterns detected.