T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:18- Finding
Unrestricted Operational Command Capability
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 18–21
Vulnerability Type:T05: Unauthorized Access and Privilege Escalation
Risk Level: Highbash ### Send instructions mcporter call MachineCommander manage_construction_machines 'order=your instruction'The snippet above is an English translation of the documented command while preserving its original semantics.
Technical Analysis
The skill documents a call to the
manage_construction_machinesendpoint that accepts an arbitrary natural-language instruction. No authorization check, target restriction, command allowlist, confirmation step, dry-run preview, or separation between read-only and state-changing operations is specified.This capability conflicts with the skill's primarily query-oriented purpose. It expands the Agent's effective permissions from retrieving equipment information to potentially controlling or changing the state of connected construction machinery. Because the MCP service implementation is external to the audited project, the exact supported commands and their effects cannot be verified from the available files.
Attack Path
- A malicious user, compromised upstream workflow, or prompt-injected context supplies an operational instruction involving connected machinery.
- The Agent interprets the instruction as eligible for the documented management workflow.
- The Agent invokes
MachineCommander manage_construction_machines, placing the untrusted instruction in theorderargument. - No skill-level confirmation, authorization, target validation, or command restriction prevents submission.
- If the external MCP service accepts and executes the instruction, the attacker may cause an unauthorized state-changing action.
Exploitation ultimately depends on the permissions and command behavior of the externally configured
MachineCommanderservice.Impact Assessment
Successful exploitation could al ...[truncated 594 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
manage_construction_machinesfrom this query-focused skill and expose it only through a separate, explicitly privileged management skill. - Require explicit user confirmation immediately before every state-changing operation, including a preview of the target machines and intended effects.
- Implement a strict allowlist of supported operations and reject unrestricted natural-language management instructions.
- Validate machine identifiers, tenant ownership, project scope, and requested actions before invoking the MCP service.
- Use a dedicated least-privilege service identity for queries. Management operations should require a separately authorized identity.
- Add role-based access control and enforce authorization server-side rather than relying solely on Agent instructions.
- Provide a dry-run mode that resolves and displays the proposed action without executing it.
- Reject management instructions originating from retrieved documents, tool output, or other untrusted indirect content.
- Record the requesting user, resolved targets, operation, confirmation, result, and timestamp in tamper-resistant audit logs.
- Define emergency controls, rate limits, and safe failure behavior for commands that could affect machinery operation.
- Remove
