T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:38- Finding
Unnecessary Shell Execution Capability Violates Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 38–40 and 339–341
Vulnerability Type: Excessive tool permissions
Risk Level: LowEvidence
yaml tools: - read - execThe capability is reiterated in the dependency notes:
text ### 可用性分类 - **分类**: MD+EXEC(纯Markdown指令,部分功能需要exec命令行执行能力) - **说明**: 基于Markdown的AI Skill,通过自然语言指令驱动Agent执行任务Technical Analysis
The skill declares access to the
exectool, which provides a command-execution channel. However, the audited skill body is an informational guide for designing no-code automation workflows. It contains no shell commands, local scripts, or documented operation that requires command execution.Granting
exectherefore exceeds the permissions necessary for the skill's stated purpose and violates the principle of least privilege. Although the current instructions do not directly invoke or abuse the capability, making it available increases the consequences of later prompt injection, untrusted workflow content, or unintended agent behavior.No active command execution, embedded malicious payload, remote payload retrieval, persistence mechanism, or credential theft was identified in the audited file.
Attack Path
- The skill is loaded with its declared
execcapability. - The agent processes later untrusted or attacker-controlled content while the skill is active.
- Malicious instructions attempt to induce the agent to issue shell commands.
- Because
execwas unnecessarily granted, those commands may run with the operating-system permissions of the hosting agent. - The resulting impact depends on the host sandbox, user privileges, and command-approval controls.
This is a potential privilege-enablement path rather than evidence that the current skill actively performs exploitation.
Impact Assessment
Successful abuse could allow command execution within the permissions and sandbox boundaries of th ...[truncated 427 chars]
- The skill is loaded with its declared
- Remediation
View remediation
Remediation Suggestions
-
Remove
execfrom the frontmatter and retain only capabilities required by the informational guide:yaml tools: - read -
Update the availability classification near lines 339–341 to describe the skill as Markdown-only rather than
MD+EXEC. -
If command execution is added in a future version, document each required command and restrict execution through an explicit allowlist.
-
Run commands in a sandbox with minimal filesystem and network access, non-privileged user permissions, and interactive approval for sensitive operations.
-
Review tool permissions whenever skill functionality changes so that unused capabilities are removed.
-
