T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:16- Finding
Unrestricted Execution Capability Exceeds the Skill's Stated Requirements
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mixes a canvas-design pitch with broad development automation, shell execution, API credentials, and administrator guidance that are not well scoped for static design work.
Review carefully before installing. Treat this as a broad automation skill, not just a design helper; only use it in a sandboxed workspace, do not provide API keys or credentials unless you know exactly what service is being called, and do not run it with administrator privileges.
SKILL.md:16Unrestricted Execution Capability Exceeds the Skill's Stated Requirements
The manifest advertises a benign visual art/poster design skill, but the declared tools and surrounding documentation introduce generic development automation and command-execution behavior. This mismatch is dangerous because it can cause the agent or user to trust and invoke a skill under false pretenses, enabling broader system interaction than expected.
The activation description is broad, mixed-language, and spans unrelated domains, making accidental invocation for inappropriate tasks more likely. When a skill also exposes read/exec tools, overly permissive routing can trigger higher-risk behavior in contexts where the user only expected harmless content creation.
The core-function section contradicts the skill's stated purpose by describing development automation, structured data processing, retries, and batch workflows instead of art generation. In an agent ecosystem, this kind of capability confusion is dangerous because policy, invocation, and user consent may be based on the claimed low-risk design role rather than the actual higher-risk automation behavior.
A skill presented as static visual design should not unexpectedly request API keys, establish external connections, or execute commands without very clear justification and warning. These undocumented operational capabilities expand the attack surface and can lead to credential exposure, unintended network access, or filesystem changes during what appears to be a low-risk design task.
The usage guidance references API-key configuration, API calls, file preparation, and command execution, but the skill does not clearly warn users up front that it may affect the local system, external services, or sensitive credentials. This lack of informed consent is risky because users may invoke what looks like a design tool without realizing it can execute commands or handle secrets.
No suspicious patterns detected.