T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:24- Finding
Overprivileged Filesystem and Command-Execution Capabilities
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24–27
Vulnerability Type: Excessive tool permissions violating least privilege
Risk Level: MediumVulnerable Code
yaml tools: - read - exec - writeRelated capability descriptions at lines 241–243:
markdown - **File processing**: Supports reading, parsing, and writing multiple file formats - **API integration**: Calls external services through standardized interfaces and processes responses - **Command execution**: Executes system commands in a secure sandbox and collects resultsTechnical Analysis
The Skill's declared purpose is to route blockchain data questions to appropriate Graph Protocol services. That task does not inherently require unrestricted local file reads, file writes, or system-command execution.
Nevertheless, the manifest requests the general-purpose
read,write, andexectools. The document does not specify:- Filesystem paths that may be accessed
- Commands or executable binaries that may be invoked
- An enforceable command allowlist
- Argument-validation rules
- Graph Protocol endpoint allowlists
- Restrictions protecting credentials and unrelated local data
Although the document recommends sandboxing and command allowlisting at line 234, these are advisory statements rather than implemented restrictions. The resulting capability set exceeds the minimum permissions needed for API request routing.
Attack Path
- An Agent loads the Skill and grants its declared
read,write, andexeccapabilities. - An attacker submits a blockchain-themed request containing a local path, crafted command argument, or instruction to process a local file.
- Because the Skill provides no enforceable path, command, or argument restrictions, the Agent may use the broad tools while attempting to satisfy the request.
- The Agent could read unrelated local information, overwrite accessible files, or run commands unrelated to Graph Protocol routing. 5 ...[truncated 1060 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
read,write, andexecfrom the tool declaration unless each capability is demonstrably required. - Replace general-purpose tools with a narrowly scoped HTTPS or Graph Protocol API client.
- Allowlist specific HTTPS endpoints and reject redirects or requests to unapproved hosts.
- If local file access is essential, restrict it to a dedicated workspace directory, reject path traversal and symbolic-link escapes, and use read-only access where possible.
- If command execution is unavoidable, use a fixed executable allowlist, pass validated arguments without shell interpolation, disable shell metacharacters, and run commands in a low-privilege sandbox with network and filesystem restrictions.
- Prevent access to environment variables, credential stores, home-directory secrets, and unrelated project files.
- Define explicit input schemas for
questionandchain, including strict length and character constraints. - Enforce output filtering so secrets, tokens, environment contents, and unrelated file data cannot be returned.
- Convert the advisory security statements into controls enforced by the hosting Agent or implementation.
- Remove
