Back to skill

Security audit

file-browser-tool

Security checks for vulnerabilities and agentic risk

Overview

This file-browser skill is presented as read-only, but it requests write and command execution capability and gives under-scoped instructions for paths, hidden files, APIs, and elevated access.

Install only if you are prepared to treat it as a review-needed skill with command execution, write capability, and possible API/network handling, not as a purely read-only local file viewer. It should be narrowed to read-only tools, explicit workspace path validation, no administrator execution guidance, and clear data-transmission rules before normal use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:20
Finding

Excessive Tool Permissions Violate the Read-Only Security Model

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:20-23
Vulnerability Type: Excessive permissions and violation of least privilege
Risk Level: Medium

Vulnerable Code

yaml
tools:
  - read
  - exec
  - write

Technical Analysis

The skill presents itself as a read-only file browser, but its configuration requests both arbitrary command execution and file-writing capabilities. Neither capability is necessary for the documented purpose of listing directories and reading files.

The write capability directly contradicts the stated read-only security model. The exec capability also provides substantially broader system access than a constrained filesystem-reading interface. Because the project contains no implementation code that enforces an allowlist of commands or otherwise constrains these permissions, the claimed read-only boundary is not established by the artifact itself.

This violates the principle of least privilege. The resulting practical exposure depends on controls independently imposed by the hosting agent, such as sandboxing, command approval, filesystem restrictions, and tool-level authorization.

Attack Path

  1. The skill is loaded with exec and write capabilities.
  2. An attacker supplies a crafted request or untrusted content that induces the agent to invoke one of those capabilities.
  3. The agent executes a system command or performs a write operation not required for read-only browsing.
  4. If the host does not independently enforce sandboxing and user approval, the operation can access or modify resources available to the agent process.

Impact Assessment

Successful exploitation could allow commands to run with the agent process's privileges or files accessible to that process to be modified. The affected scope may extend beyond the intended SkillHub workspace when the host environment does not impose its own filesystem boundary.

The artifact does not contain instructions for persistence, destructive ...[truncated 131 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove write from the declared tools.
  2. Replace unrestricted exec with a dedicated, read-only filesystem API.
  3. If command execution is unavoidable, permit only fixed operations with structured arguments rather than arbitrary shell strings.
  4. Configure the runtime with a read-only workspace mount and deny access outside that mount.
  5. Require explicit user approval for any operation beyond directory listing and file reading.
  6. Add tests verifying that the skill cannot create, modify, rename, or delete files.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:148
Finding

Unrestricted File Paths and Shell-Based Reads Lack an Enforced Workspace Boundary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:148-149, 233, 276-287, 304
Vulnerability Type: Unvalidated path access and insecure command-based file handling
Risk Level: Medium

Vulnerable Code

text
### Q2: Does the file browser tool support reading hidden files?
A: Yes, file browser tools generally support reading hidden files. Hidden files may not be displayed in the filesystem, but the tool can display and read their contents through specific parameters or commands.
text
| rel_path | string | unrestricted | none | Relative path of the file |
bash
execute("ls", ["./"])
bash
execute("cat", ["./example.txt"])
bash
execute("cat", ["./example.txt"], {"mode": "markdown"})
text
If the file belongs to the system or another user, you may need to run the tool as an administrator or request the corresponding permissions.

The excerpts above are English translations of the relevant text in SKILL.md; the command examples are reproduced verbatim.

Technical Analysis

The documentation claims that paths are relative to a workspace, but it defines rel_path as unrestricted and provides no implementation that validates or canonicalizes paths. The generic ls and cat examples do not independently enforce a workspace root.

Consequently, the audited artifact does not demonstrate rejection of:

  • Absolute paths.
  • Parent-directory traversal such as ../.
  • Symbolic links that resolve outside the workspace.
  • Device or special-file paths.
  • Sensitive hidden files.
  • Paths exceeding the documented depth constraints.

Supporting hidden-file reads increases the possibility of exposing credentials, configuration files, tokens, or repository metadata. The recommendation to use administrator privileges is particularly unsafe because it expands the set of files the process can access rather than correcting authorization or boundary failures.

There is no executable implementation in the project, so actual e ...[truncated 1315 chars]

Remediation
View remediation

Remediation Suggestions

  1. Implement file access through a dedicated read-only API rather than ls, cat, or arbitrary command execution.
  2. Reject absolute paths, null bytes, device paths, and parent-directory traversal components.
  3. Resolve the requested path and workspace root to canonical paths, then require the resolved target to remain beneath the canonical workspace root.
  4. Define an explicit symbolic-link policy. Prefer rejecting symlinks or verify containment after every resolution step.
  5. Deny hidden and sensitive files by default, with a narrow allowlist when access is genuinely required.
  6. Open files using race-resistant mechanisms where available to reduce time-of-check/time-of-use and symlink-race risks.
  7. Enforce the documented file-size, encoding, directory-depth, and recursion limits in implementation code.
  8. Remove the recommendation to use administrator or root privileges. Return a permission error instead.
  9. Add tests for ../ traversal, absolute paths, nested traversal, symlink escapes, hidden files, special files, and paths sharing only a textual prefix with the workspace root.
  10. Document the runtime sandbox as a mandatory security control rather than implying that Markdown instructions alone provide confinement.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest and summary present this skill as a read-only workspace file browser, but the declared tools include exec and write and the body advertises broader command, API, and processing capabilities. This mismatch can mislead users or orchestration logic into granting or invoking more powerful behavior than expected, increasing the risk of unauthorized file modification, command execution, or data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill presents itself as read-only file browsing while exposing execute capability without a clear, prominent warning. Hidden command execution is dangerous because users may authorize or invoke the skill under the assumption of passive file access, enabling arbitrary shell actions if the backing implementation is permissive.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation references LLM/API dependencies and external integration but does not prominently warn that file contents may be sent to remote services. For a file-reading skill, undisclosed outbound transmission can expose sensitive workspace data and violates the expectation of local-only processing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation repeatedly assures users that operations are read-only and prevent accidental changes, yet elsewhere describes write support and even advises backing up before modifying files. Contradictory safety claims create a dangerous trust boundary failure: users may expose sensitive paths or approve execution assuming no state-changing action is possible.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says to use the skill whenever '需要文件处理、文档转换、格式互转、内容提取' without clearly delimiting what operations are actually supported. This broad natural-language trigger overlaps with many common tasks and does not provide specific activation constraints or negative examples beyond encrypted-file cracking.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is branded as a file browser, but the documentation advertises unrelated security scanning, threat intelligence, and risk scoring features. This scope inflation can cause operators or agents to invoke the skill in inappropriate contexts and normalize hidden or future-expanded capabilities that exceed the expected trust model.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The scenario table includes generic categories like '安全检查', '文件操作', and 'SkillHub工作' with broad input/output descriptions. These labels are not specific enough for a supposedly read-only file browser and may cause the skill to be selected for unrelated scanning or operational tasks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill claims paths are constrained to a workspace-relative model, but the parameter documentation says rel_path has no limits and examples show raw shell commands like ls and cat. Without clear normalization and enforcement, users or agents may assume containment that does not actually exist, enabling path traversal or access beyond the intended workspace.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation introduces API integration, external service calls, and network-dependent behavior despite the skill's local read-only file browsing purpose. This expands the attack surface and creates a risk that file contents or metadata could be transmitted off-host without users clearly understanding that a local file tool may perform remote interactions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The user-facing name and core descriptive text are partly Chinese and partly English, with no indication that the user can choose a preferred language or locale. This may violate a language/locale policy requiring opt-in or explicit language choice for user-facing skill behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.