T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:24- Finding
Overbroad Tool Permissions and Unsafe Privilege-Escalation Guidance
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24–27, 254–256, 269, and 291
Vulnerability Type: Excessive system capabilities and privilege-escalation guidance
Risk Level: MediumVulnerable Code
Lines 24–27 declare unrestricted general-purpose file and command-execution tools:
yaml tools: - read - exec - writeLines 254–256 further state that the Skill supports reading and writing files and executing system commands. Lines 269 and 291 recommend running with administrator privileges when file permissions are insufficient.
Technical Analysis
The Skill is presented as browser automation, but it requests generic filesystem read, filesystem write, and command-execution capabilities without defining command allowlists, path restrictions, sandbox boundaries, or approval requirements. These capabilities exceed what is strictly required for browser navigation and page extraction.
The document also recommends administrator execution as a generic remedy for insufficient file permissions. Elevating the entire agent or automation environment rather than correcting the specific permission boundary violates the principle of least privilege. If untrusted task input or webpage content influences agent actions, these broad tools could be used against resources unrelated to the browser-automation task.
The document claims commands run in a secure sandbox, but it does not provide an enforceable sandbox configuration. Documentation alone does not establish a security boundary.
Attack Path
- A user submits an automation request involving an attacker-controlled website, or the browser encounters attacker-controlled page content.
- The content induces the agent to read a local file, write an unrelated file, or invoke a system command as part of the purported automation workflow.
- The Skill's declared
read,write, andexectools permit the agent to attempt the requested operation.
...[truncated 1163 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove generic
read,write, andexeccapabilities unless each capability is necessary for a documented browser operation. - Replace unrestricted command execution with a narrow interface that exposes only approved
agent-browsersubcommands and validated arguments. - Enforce a command allowlist and reject shell metacharacters, command substitution, redirects, pipelines, and arguments derived directly from untrusted page content.
- Restrict filesystem operations to a dedicated workspace using canonical-path validation, deny path traversal, and prohibit access to credentials, configuration directories, and system files.
- Require explicit user confirmation before downloads, file writes, command execution, authentication actions, or other externally visible side effects.
- Remove the recommendation to run as administrator. Troubleshooting should instead identify the required resource and grant only the minimum specific permission.
- Implement the claimed sandbox as an enforceable control, such as an unprivileged container with a read-only root filesystem, isolated temporary storage, restricted networking, and no host credential mounts.
- Treat webpage text and extracted content as untrusted data rather than agent instructions.
- Document the required
agent-browserversion and installation source so the external executable can be independently verified.
- Remove generic
