T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:10- Finding
Excessive GitHub Scopes and Blanket Elevated Network Access
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10-12
Vulnerability Type: Excessive permissions and unnecessary privilege escalation
Risk Level: MediumVulnerable Code Snippet:
markdown Guide to find the open PR for the current branch and address its comments with gh CLI. Run all `gh` commands with elevated network access. Prereq: ensure `gh` is authenticated (for example, run `gh auth login` once), then run `gh auth status` with escalated permissions (include workflow/repo scopes) so `gh` commands succeed. If sandboxing blocks `gh auth status`, rerun it with `sandbox_permissions=require_escalated`.Technical Analysis
The skill directs the agent to run every GitHub CLI command with elevated network access and to use credentials that include broad
repoandworkflowscopes. This conflicts with the principle of least privilege.The bundled implementation only performs read operations: it obtains pull-request metadata with
gh pr viewand retrieves comments, reviews, and review threads throughgh api graphql. Theworkflowscope is not required for those operations and can authorize sensitive changes to GitHub Actions workflow files. Blanket escalation of all GitHub CLI commands is also broader than the demonstrated need for narrowly scoped network access.The script itself does not directly modify workflows or misuse the credential. The risk arises because the skill establishes an unnecessarily privileged execution and authentication context that another compromised component, malicious repository instruction, or later command could abuse.
Attack Path
- A user invokes the skill to inspect or address pull-request comments.
- The skill directs the agent to authenticate GitHub CLI with broad
repoandworkflowscopes. - It also directs the agent to execute all
ghcommands with elevated network access, including retrying outside normal sandbox restrictions. - A compromis ...[truncated 1052 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to include the
workflowscope because the current implementation does not modify workflow files. - Use a fine-grained GitHub token with read-only access to pull requests and repository metadata for comment retrieval.
- Separate read and write operations. Request additional authorization only after the user selects comments and a concrete repository modification is necessary.
- Replace the blanket instruction to elevate all
ghcommands with narrowly scoped network elevation for only the specific GitHub API calls that require it. - Do not treat failure of
gh auth statusas sufficient justification to bypass sandbox restrictions automatically. Explain the required access and obtain explicit user approval before escalation. - Document the minimum required GitHub permissions and validate them before execution. Reject credentials that are insufficient, but do not instruct users to grant unrelated scopes.
- Preserve the existing use of argument arrays without a shell in
scripts/fetch_comments.py, which reduces command-injection exposure.
- Remove the instruction to include the
