T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:18- Finding
Overly Broad Tool Permissions Violate Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 18
Vulnerability Type:T05: Unauthorized Access and Privilege Escalation
Risk Level: MediumVulnerable Code:
yaml allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) AgentTechnical Analysis
The skill grants unrestricted
Bash(git:*)access and the general-purposeAgentcapability. Its documented purpose is limited to reviewing and improving Gocontext.Contextusage, for which file inspection, editing, Go commands, and linting are sufficient.Broad Git access can modify repository state, configuration, branches, remotes, hooks, or tracked content, depending on the execution environment. The
Agentpermission may also permit delegation that expands the effective action surface beyond the immediate context-analysis task. Neither capability is required by the documented workflows.This violates the principle of least privilege. Although the reviewed skill contains no explicit instruction to abuse these permissions, unnecessary capabilities increase the consequences of malicious or misleading repository content encountered while the skill is active.
Attack Path
- An attacker places adversarial or misleading instructions in repository content that the skill is asked to inspect.
- The agent reads that content while operating with the permissions declared in
allowed-tools. - The content induces the agent to invoke an unnecessary
gitoperation or delegate work throughAgent. - The resulting operation may alter repository state, inspect Git configuration, manipulate remotes, or perform delegated actions outside the skill’s legitimate context-review scope.
- These actions occur with permissions that would not have been available under a narrowly scoped tool policy.
This is a conditional exploitation path: successful abuse depends on the host agent honoring the declared permissions and bein ...[truncated 500 chars]
- Remediation
View remediation
Remediation Suggestions
Apply a least-privilege tool policy:
- Remove
Bash(git:*)unless a specific, documented Git operation is essential. - Remove
Agentunless delegation is necessary for a defined workflow. - Retain only the capabilities needed for the stated task, such as:
yaml allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) - Where supported by the host, constrain read and write access to the declared
**/*.gopath scope. - If Git access later becomes necessary, allowlist individual read-only commands rather than the entire
git:*command family. - Require explicit user confirmation before repository-mutating operations or delegation outside the direct audit task.
- Remove
