T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:4- Finding
Overly Broad Python Execution Permission Violates Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 4
Vulnerability Type: Overly broad interpreter execution permission
Risk Level: Mediumyaml allowed-tools: Read, WebSearch, WebFetch, Skill, Bash(python3:*), Bash(python:*)Technical Analysis
The Skill only needs to run its bundled entry point,
scripts/workbuddy_shopping.py. However, the wildcard permissionsBash(python3:*)andBash(python:*)authorize the interpreters with arbitrary arguments rather than limiting execution to that entry point.Depending on the host's tool-policy semantics, this can permit commands such as
python3 -c '<code>', execution of arbitrary local scripts, or Python standard-library calls that access files, create network connections, and launch child processes. The restrictions implemented by the bundled shopping engine do not constrain separate interpreter commands invoked through this broad permission.No evidence indicates that the bundled code abuses this capability. The risk arises from granting more execution authority than the Skill's legitimate functionality requires.
Attack Path
- The Skill is loaded with wildcard permission to invoke
pythonorpython3. - A malicious webpage, conflicting instruction, or other untrusted content attempts to induce a Bash call using one of those interpreters.
- The command satisfies the broad interpreter allowlist even if it does not invoke
scripts/workbuddy_shopping.py. - Arbitrary Python code executes with the operating-system privileges and resource access available to the Agent process.
- That code may access readable files, contact external systems, or start subprocesses where the runtime sandbox permits those operations.
Exploitation still requires an instruction path capable of inducing an unintended tool call and is subject to any additional sandbox controls enforced by the host.
Impact Assessment
Successful exploitation could bypass the ...[truncated 477 chars]
- The Skill is loaded with wildcard permission to invoke
- Remediation
View remediation
Remediation Suggestions
- Replace wildcard interpreter permissions with a rule restricted to the exact bundled entry point:
scripts/workbuddy_shopping.py- The explicitly required flags, such as
--self-testand--version - JSON input supplied through standard input
- Explicitly deny interpreter options that execute arbitrary code, particularly
-c,-m, interactive mode, and arbitrary script paths. - Prefer a dedicated non-shell tool or fixed wrapper that:
- Accepts only a JSON object.
- Enforces the 4 MB input limit.
- Invokes only the bundled engine.
- Uses a fixed working directory and sanitized environment.
- Rejects unknown flags and paths.
- Apply runtime sandboxing even after narrowing the allowlist:
- Disable outbound networking.
- Restrict filesystem access to required read-only resources.
- Prevent child-process creation.
- Run with a low-privilege operating-system identity.
- Add a release-time policy test that fails if wildcard Python or unrestricted shell permissions are reintroduced.
- Replace wildcard interpreter permissions with a rule restricted to the exact bundled entry point:
