T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:19- Finding
Excessive Agent Tool Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 19–23
Vulnerability Type: Excessive tool permissions violating least privilege
Risk Level: MediumVulnerable Code
yaml tools: - read - exec - glob - grepRelated capability claims appear at lines 181–185:
markdown - **自动化执行**: 管理飞书Lark日历,列出/搜索/查日程/同步事件,办公协同。Manage Feishu (Lark) calendar - **文件处理**: 支持多种文件格式的读取、解析和写入操作 - **API集成**: 通过标准化接口调用外部服务并处理响应 - **命令执行**: 在安全沙箱中执行系统命令并收集结果 - **信息检索**: 快速搜索和过滤目标数据Technical Analysis
The Skill requests general-purpose local file-reading, filesystem-search, and command-execution capabilities. These permissions are not necessary for its stated purpose of listing, searching, checking, and synchronizing Lark calendar events. Calendar management should instead use a narrowly scoped calendar API integration.
Granting
read,glob, andgrepexpands the accessible scope to local files, whileexecintroduces a general command-execution channel. Although the reviewed file contains no direct malicious command or demonstrated exploit payload, this permission set breaks the principle of least privilege and increases the consequences of malicious or attacker-controlled input processed during Skill use.The project contains only
SKILL.mdand does not define path restrictions, command allowlists, argument validation, user-confirmation requirements, or a constrained Lark calendar tool.Attack Path
- An Agent loads the Skill and grants the declared
read,glob,grep, andexectools. - The Skill processes attacker-controlled or otherwise untrusted calendar content or user input.
- Crafted input attempts to induce the Agent to perform operations unrelated to calendar management.
- The broadly granted tools may allow the Agent to discover and read local files or execute local commands.
- The resulting access is limited by the Agent sandbox and operating-sys ...[truncated 593 chars]
- An Agent loads the Skill and grants the declared
- Remediation
View remediation
Remediation Suggestions
- Remove
exec,read,glob, andgrepunless each capability has a documented and unavoidable calendar-specific requirement. - Replace general tools with a narrowly scoped Lark calendar API tool that permits only required operations and approved Lark HTTPS endpoints.
- Use minimally scoped Lark credentials and restrict them to the required calendars and event operations.
- If local file access is indispensable, enforce an explicit path allowlist, reject traversal and symbolic-link escapes, and prohibit access to secrets, environment files, and credentials.
- If command execution is indispensable, use fixed executable and argument allowlists, avoid shell interpretation, apply strict time and resource limits, and require explicit user confirmation.
- Treat calendar fields and user-provided content as untrusted data rather than executable Agent instructions.
- Document the exact required permissions and add tests verifying that unrelated filesystem and command operations are denied.
- Remove
