T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:114- Finding
Autonomous Social Media Publishing Without Per-Post Authorization
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8, 114-118, and 177
Vulnerability Type: Unauthorized use of an authenticated browser session
Risk Level: HighRelevant instructions translated into English:
markdown 1. **Fully automated publishing** — The MCP browser automatically executes the publishing process and notifies the owner only if it fails.markdown When the hourly cron job is triggered: - Analyze whether there are suitable current trends - Generate content - Automatically execute the publishing process - Success: notify the owner with a brief confirmation - Failure: notify the owner and provide the complete contentmarkdown - **Fully automated publishing**: Automatically execute the publishing process whether or not the owner is at the computer; notify the owner only if it fails.Technical Analysis
The Skill directs the agent to use an authenticated MCP browser session to perform an irreversible external action—publishing content to X or Weibo—without obtaining explicit approval immediately before submission. The owner is informed only after the operation succeeds or fails.
This behavior violates least-privilege and human-in-the-loop principles. Permission to access an authenticated browser session does not necessarily imply standing authorization to publish arbitrary generated content. The risk is increased by the hourly cron workflow, which can repeatedly generate and submit posts while the owner is absent.
The instructions are also internally inconsistent with other language suggesting that the owner may choose whether to publish. The unconditional automated-publishing directives can override that safer workflow.
No evidence was found that the Skill can obtain credentials, bypass authentication, take over an account, or access privileges beyond those already available in the browser session. The exposed capability ...[truncated 1545 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace automatic submission with a draft-only workflow for all cron and unattended executions.
- Require explicit, per-post confirmation immediately before activating the final publishing control.
- Present the platform, authenticated account, complete final content, links, and hashtags in the approval prompt.
- Treat approval as single-use and bind it to the exact content shown; require renewed approval after any edit.
- Default the MCP workflow to dry-run mode and expose publishing as a separately authorized action.
- Remove or rewrite the unconditional automated-publishing directives at lines 8 and 177.
- Add rate limits, duplicate detection, daily posting caps, and a global emergency-disable control.
- Record the approving user, approved content hash, destination platform, account, timestamp, and publication result in an audit log.
- Restrict the browser profile used by the Skill to only the necessary accounts and permissions.
- On browser errors, authentication changes, unexpected redirects, or content mismatches, stop safely rather than retrying submission automatically.
