T01 · Skill Instruction Hijacking
- Location
chat.js:727- Finding
Unauthenticated Remote Messages Execute Claude Code Without Permission Checks
- Content
View full analysis
{ const child = spawn('claude', ['-p', prompt, '--dangerously-skip-permissions'], { cwd: projectDir || process.cwd(), stdio: ['ignore', 'pipe', 'pipe'], }); ``` The task is populated directly from a received OceanBus message: ```js if (autoExec) { taskQueue.push({ fromName: fromName || msgFrom, fromOpenid: msg.from_openid, body, }); console.log('[auto-exec] Task queued: ' + taskQueue.length); processQueue(); return; } ``` The monitor command contains the same unsafe execution pattern: ```js if (autoExec && content.trim()) { const prompt = content; const label = fromName; try { const result = await new Promise((resolve, reject) => { const child = spawn('claude', ['-p', prompt, '--dangerously-skip-permissions'], { cwd: projectDir || process.cwd(), stdio: ['ignore', 'pipe', 'pipe'], }); ``` ### Technical Analysis When `--auto-exec` is enabled, the body of every received message is passed directly to Claude Code as its prompt. The command explicitly supplies `--dangerously-skip-permissions`, disabling the normal permission boundary around filesystem access, command execution, network access, and other tools available to Claude Code. No sender allowlist, challenge-response authentication, local confirmation, per-task authorization, prompt isolation, or capability restriction is applied before execution. The listener also automatically creates contacts for previously unknown senders, so roster membership does not constitute an authorization boundary. Although enabling `--auto-exec` requires a local command-line option, the resulting execution ...[truncated 1760 chars]- Remediation
View remediation
