T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:545- Finding
Generated curriculum spreadsheets are unconditionally exposed through anonymous public sharing
- Content
View full analysis
--to anyone --role reader` ``` ### Technical Analysis The Skill explicitly instructs the agent to change each generated spreadsheet's access-control list to permit anonymous Internet-wide read access. The instruction is unconditional and does not request the user's consent, evaluate the sensitivity of the curriculum, or offer a restricted-sharing alternative. Public access is not required to perform the declared curriculum-design function. A spreadsheet could remain private, be returned to its owner, or be shared with specified users or an approved organization domain. Consequently, the instruction exceeds the minimum permissions necessary for the task. Generated content can include POD names, target-audience details, subject requirements, teacher capability information, and organizational curriculum plans. Although the granted role is read-only, it removes authentication and authorization boundaries for that information. ### Attack Path 1. A user invokes the Skill to create a curriculum. 2. The workflow gathers potentially organization-specific educational and teacher-context information. 3. The Skill creates a spreadsheet using the authenticated user's Google account. 4. The documented command changes the spreadsheet ACL to `anyone` with the `reader` role. 5. The public URL is returned or otherwise distributed. 6. Any party that obtains the URL can read the spreadsheet without ...[truncated 895 chars]- Remediation
View remediation
