T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:6- Finding
Unnecessary Permission to Access User Information
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:6
Vulnerability Type: Excessive tool permission violating least privilege
Risk Level: LowVulnerable Code
yaml allowed-tools: ["Bash(fdx status*)", "Bash(fdx call getWalletOverview*)", "Bash(fdx call getMyInfo*)"]Technical Analysis
The skill permits invocation of
fdx call getMyInfo*, although none of its documented funding workflows requires that command. Authentication checks usefdx status, while wallet-address and balance retrieval usefdx call getWalletOverview.Granting
getMyInfo*access therefore exceeds the minimum permissions needed to fund a wallet. The wildcard also permits any command-line suffix accepted by the tool policy and command. An erroneous instruction or malicious content influencing the agent could cause it to retrieve user-profile information unrelated to the requested funding task.There is no evidence that this skill currently invokes the command or transmits its output externally. The finding is limited to unnecessary access capability, not confirmed data theft.
Attack Path
- A user invokes the wallet-funding skill.
- The agent receives permission to execute
fdx call getMyInfo*. - Malicious contextual content, prompt injection, or an agent error directs the agent to invoke that permitted command.
- The Finance District CLI returns user information that is unnecessary for wallet funding.
- The resulting information becomes exposed in the agent's execution context or command output.
Impact Assessment
Exploitation could disclose user-account or profile information returned by
getMyInfoto the active agent session. The precise data scope depends on the Finance District API response and the authenticated user's privileges. The reviewed file provides no evidence that this permission enables privilege elevation, transaction execution, persistence, or external exfiltration.- Remediation
View remediation
Remediation Suggestions
Remove the unused
getMyInfocapability and retain only commands required by the documented workflow:yaml allowed-tools: ["Bash(fdx status*)", "Bash(fdx call getWalletOverview*)"]Additionally:
- Replace wildcard command permissions with exact argument patterns where the skill framework supports them.
- Review each future tool addition against a documented workflow requirement before granting access.
- Ensure outputs containing wallet or account information are displayed only when necessary and are not persisted or transmitted.
- Add a least-privilege review to skill maintenance and release checks.
