T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:34- Finding
Unnecessary Command-Execution Capability Violates Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 34–36
Vulnerability Type: Excessive tool permission
Risk Level: MediumEvidence
yaml tools: - read - execTechnical Analysis
The skill declares access to the
exectool even though its documented purpose and execution protocol consist solely of reading, analyzing, summarizing, comparing, and rewriting documents. No legitimate workflow in the reviewed file requires shell-command execution.Exposing
execunnecessarily violates the principle of least privilege. Although the current instructions do not directly invoke commands, documents processed by the skill may contain hostile prompt-injection content. If an agent treats such content as instructions, the availability ofexeccould turn a document-level instruction-manipulation issue into local command execution.No direct command-execution payload, malicious script, or explicit instruction to execute document content was found. Exploitation therefore depends on the hosting agent allowing document content or other untrusted input to influence tool calls.
Attack Path
- A user or external source supplies a malicious document for analysis.
- The document includes prompt-injection text directing the agent to disregard the analysis workflow and invoke the command-execution tool.
- The agent fails to maintain the distinction between untrusted document content and trusted skill instructions.
- Because
execis declared as an available tool, the agent invokes a local command. - The command operates with the permissions of the agent process and may access or modify resources available to that process.
Impact Assessment
Successful exploitation could permit command execution under the operating-system identity running the agent. Depending on the host sandbox and process privileges, this could expose readable local files, environment variables, workspace content, or writable resources and could allow data modifica ...[truncated 288 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
execfrom the declared tool list and retain only the minimum capability required:
yaml tools: - read- Change the availability classification from
MD+EXECto a Markdown-only classification so that the metadata accurately reflects the implementation. - Configure the host agent to treat analyzed document content as untrusted data rather than executable instructions.
- Require explicit user confirmation and restrictive sandboxing for any future feature that genuinely needs command execution.
- If command execution is later introduced, use a narrowly scoped allowlist of fixed commands and arguments rather than unrestricted shell access.
- Deny access to credentials, sensitive environment variables, and files outside the required workspace from any command-execution sandbox.
- Remove
