T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:20- Finding
Excessive Tool Permissions Violate the Read-Only Security Model
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:20-23
Vulnerability Type: Excessive permissions and violation of least privilege
Risk Level: MediumVulnerable Code
yaml tools: - read - exec - writeTechnical Analysis
The skill presents itself as a read-only file browser, but its configuration requests both arbitrary command execution and file-writing capabilities. Neither capability is necessary for the documented purpose of listing directories and reading files.
The
writecapability directly contradicts the stated read-only security model. Theexeccapability also provides substantially broader system access than a constrained filesystem-reading interface. Because the project contains no implementation code that enforces an allowlist of commands or otherwise constrains these permissions, the claimed read-only boundary is not established by the artifact itself.This violates the principle of least privilege. The resulting practical exposure depends on controls independently imposed by the hosting agent, such as sandboxing, command approval, filesystem restrictions, and tool-level authorization.
Attack Path
- The skill is loaded with
execandwritecapabilities. - An attacker supplies a crafted request or untrusted content that induces the agent to invoke one of those capabilities.
- The agent executes a system command or performs a write operation not required for read-only browsing.
- If the host does not independently enforce sandboxing and user approval, the operation can access or modify resources available to the agent process.
Impact Assessment
Successful exploitation could allow commands to run with the agent process's privileges or files accessible to that process to be modified. The affected scope may extend beyond the intended SkillHub workspace when the host environment does not impose its own filesystem boundary.
The artifact does not contain instructions for persistence, destructive ...[truncated 131 chars]
- The skill is loaded with
- Remediation
View remediation
Remediation Suggestions
- Remove
writefrom the declared tools. - Replace unrestricted
execwith a dedicated, read-only filesystem API. - If command execution is unavoidable, permit only fixed operations with structured arguments rather than arbitrary shell strings.
- Configure the runtime with a read-only workspace mount and deny access outside that mount.
- Require explicit user approval for any operation beyond directory listing and file reading.
- Add tests verifying that the skill cannot create, modify, rename, or delete files.
- Remove
