T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:13- Finding
Unnecessary Access to Global Agent Configuration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 13
Vulnerability Type: Access outside the project and task boundary
Risk Level: HighVulnerable Code
markdown このスキルは、以下のガイドライン(`~/.claude/CLAUDE.md`)に基づいた体系的なコードレビューを提供します:The instruction states that the Skill bases its operation on the global
~/.claude/CLAUDE.mdfile.Technical Analysis
The Skill's declared function is to review source code. That task ordinarily requires read access only to the selected project, its changes, and optionally its pull-request metadata. Accessing a global Agent configuration file falls outside this scope.
A global configuration file may contain private user preferences, operating instructions, tool configuration, or rules shared across unrelated projects. It may also contain persistent instructions introduced by another project or process. Loading it expands the Skill's trust boundary and creates a route through which unrelated or attacker-controlled instructions could influence the current review.
The audited files do not contain a direct mechanism that transmits the contents of this file, so direct exfiltration is not established. The confirmed issue is unnecessary cross-project configuration access and the resulting instruction-poisoning exposure.
Attack Path
- An attacker or compromised process modifies
~/.claude/CLAUDE.md. - A user invokes this code-review Skill on an otherwise trusted project.
- The Skill follows
SKILL.mdand loads or relies on the global configuration. - Malicious persistent instructions alter review behavior, request additional access, conceal findings, or cause disclosure of contextual information.
- The altered behavior affects a project unrelated to the source of the malicious configuration.
Impact Assessment
Successful exploitation could influence the Agent across project boundaries and expose user-specific operating context. The accessible scope depends on the contents of the global file a ...[truncated 321 chars]
- An attacker or compromised process modifies
- Remediation
View remediation
Remediation Suggestions
- Remove the dependency on
~/.claude/CLAUDE.md. - Store all review criteria required by the Skill inside the Skill package.
- If external configuration is optional, require explicit user approval before accessing a named file.
- Restrict external configuration to an allowlisted path and document exactly which fields are used.
- Treat externally loaded instructions as untrusted data and prevent them from overriding system, safety, scope, or authorization constraints.
- Ensure the Skill remains functional with project-scoped read access only.
- Remove the dependency on
