T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:15- Finding
Excessive Tool Permissions Violate Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 15
Vulnerability Type: Excessive tool authorization
Risk Level: MediumComplete Code Snippet:
yaml allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent WebFetch WebSearch AskUserQuestion mcp__context7__resolve-library-id mcp__context7__query-docs Bash(godig:*) Bash(gopls:*) LSP mcp__gopls__*Technical Analysis
The Skill's documented purpose is to recommend and compare Go libraries. That workflow primarily requires reading and searching project files and consulting library documentation. The declared permissions additionally authorize file mutation through
EditandWrite, subprocess execution through broad Go, Git, linting, and documentation command families, and action delegation throughAgent.These capabilities exceed the minimum privileges needed for the stated task. In particular:
EditandWritepermit modification or creation of project files.Bash(go:*)can invoke project-controlled build steps, tests, generators, or other executable Go workflows.Bash(git:*)can alter repository state and configuration, in addition to performing read-only inspection.Agentallows delegation beyond the direct recommendation workflow.- Wildcard command families authorize more operations than individually scoped, read-only commands would.
The reviewed instructions do not direct the agent to misuse these permissions. This finding therefore concerns excessive privilege and expanded attack surface, not confirmed malicious execution.
Attack Path
- The Skill is activated while the agent is evaluating a dependency in a repository containing untrusted instructions, source content, generated metadata, or tool configuration.
- That untrusted content influences the agent to perform an operation unrelated to library recommendation.
- The agent uses an unnecessarily authorized capabilit ...[truncated 942 chars]
- Remediation
View remediation
Remediation Suggestions
Apply least privilege to the
allowed-toolsdeclaration:- Retain only capabilities required to inspect the project and research library facts, such as
Read,Glob,Grep,WebSearch, narrowly constrainedWebFetch, and read-only documentation or language-server tools. - Remove
EditandWritebecause the documented recommendation workflow does not require project mutation. - Remove
Agentunless delegation is explicitly required and its security boundaries are documented. - Replace wildcard Bash families with individually approved, read-only commands. Avoid
Bash(git:*); if repository inspection is necessary, allow only specific commands such as status or log operations through an enforceable command policy. - Remove
Bash(go:*)and other executable tool families unless a separate workflow requires them. If retained, explicitly prohibit generators, installation, arbitrary test execution, and project-controlled build hooks. - Separate advisory and project-modification functionality into different Skills so users can grant elevated permissions only when mutation is explicitly requested.
- Add documentation stating that repository content and fetched documentation are untrusted data and must not be treated as executable instructions.
- Retain only capabilities required to inspect the project and research library facts, such as
