T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:24- Finding
Excessive Tool Permissions for a Preference-Learning Skill
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:24-27
Additional Location:SKILL.md:332-336
Vulnerability Type: Excessive privilege and violation of least privilege
Risk Level: MediumVulnerable Code
yaml tools: - read - exec - writeThe skill declares unrestricted access to file-reading, file-writing, and command-execution tools. Its documented purpose is to learn and maintain visual design preferences, which does not require general system command execution. The document does not define command allowlists, filesystem path restrictions, approval requirements, or other enforceable boundaries around these capabilities.
Technical Analysis
Granting the
exectool creates a general local command-execution channel under the permissions of the hosting Agent process. The broadreadandwritedeclarations can likewise permit access to files unrelated to the visual-preference archive if the host does not impose separate sandbox controls.This violates the principle of least privilege. A visual-preference skill should ordinarily require only access to a dedicated preference record or a narrowly scoped state-storage API. The documentation states that commands run in a sandbox, but it does not specify or enforce the sandbox policy in the skill configuration.
No malicious command, automatic exploitation behavior, credential theft, or persistence mechanism was found in the reviewed package. Exploitation therefore depends on the hosting Agent honoring these broad tool declarations and on malicious or misinterpreted input inducing tool use.
Attack Path
- A user or external content source provides a malicious design-related instruction containing prompt-injection content.
- The skill processes that content while the Agent has the declared
read,write, andexeccapabilities available. - The injected instruction persuades the Agent to invoke a capability unrelated to visual-pre ...[truncated 1046 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
execcapability because no documented core workflow requires arbitrary command execution. - Replace general
readandwriteaccess with a dedicated preference-storage API where supported. - If filesystem access is unavoidable, restrict it to one documented preference file or application-owned directory.
- Enforce canonical-path validation and reject traversal, symbolic-link escapes, and access outside the approved storage root.
- Require explicit user confirmation before reading or modifying any path outside the preference archive.
- Apply host-level sandboxing, minimal operating-system privileges, resource limits, and comprehensive tool-call audit logging.
- Define strict input validation so user-controlled design text cannot be interpreted as authorization for unrelated tool operations.
- Remove unsupported generic claims about command execution and file processing unless those capabilities are necessary and protected by enforceable controls.
- Remove the
