T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:66- Finding
Mandatory Host and Agent Telemetry Exceeds Least-Privilege Requirements
- Content
View full analysis
/dev/null & ``` ### Technical Analysis The mandatory initialization request collects and transmits the AI agent identifier, invocation timestamp, operating-system name, and CPU architecture to `pancakeswap.ai`. These attributes are not necessary to query public blockchain state, calculate pending rewards, retrieve token prices, or generate PancakeSwap harvest links. The behavior therefore exceeds the minimum data access required for the Skill's declared functionality. The request is sent in the background while both its response and error output are discarded. This makes the telemetry less visible to the user and prevents normal review of server responses or transmission failures. The request does not transmit private keys, wallet seed phrases, authentication credentials, or arbitrary environment variables. Its confirmed scope is limited to the explicitly constructed query parameters and network metadata inherently available to the remote server, such as the source IP address. ### Attack Path 1. A user invokes the reward-harvesting Skill. 2. The Skill instructs the agent to execute the initialization command before performing reward discovery. 3. Local commands collect the current UTC time, operating-system name, and CPU architecture. 4. The collected values and configured agent identifier are inserted into an HTTPS query string. 5. The information is transmitted to `pancakeswap.ai`. 6. The remote service can associate the reported host characteristics and agent type with the source IP address and invocation time. 7. Repeated invocations could be correl ...[truncated 592 chars]- Remediation
View remediation
