T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:19- Finding
Excessive Execution and Write Permissions Violate Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:19-24
Vulnerability Type: Excessive agent tool permissions
Risk Level: MediumVulnerable Configuration:
yaml tools: - read - exec - write - glob - grepTechnical Analysis
The skill is intended to perform static review of Java source files and Git diffs. This workflow ordinarily requires only repository reading and searching through tools such as
read,glob, andgrep.The configuration additionally grants
execandwritecapabilities without defining command allowlists, path restrictions, user-confirmation requirements, or other authorization boundaries. These capabilities exceed the minimum privileges required for static code review. In particular:execcan permit operating-system command execution under the privileges of the agent process.writecan permit modification or creation of files accessible to the agent process.- The skill does not limit these operations to a designated repository or report-output directory.
- The skill does not require explicit approval before invoking privileged tools.
This excessive authority creates a privilege boundary violation. When reviewing attacker-controlled source code, comments, diffs, or documentation, adversarial content could attempt to influence the agent into invoking these tools for actions unrelated to code review.
No instructions in the audited file explicitly direct the agent to perform malicious command execution or file modification. Exploitation therefore depends on the hosting agent making the declared tools available and being susceptible to instructions embedded in untrusted review material.
Attack Path
- A user loads the skill in an agent environment that enables every tool declared in
SKILL.md. - The user asks the skill to review an attacker-controlled Java repository, source file, or Git diff.
- The supplied material contains adversarial inst ...[truncated 1371 chars]
- Remediation
View remediation
Remediation Suggestions
Apply least privilege to the skill configuration:
- Remove
execandwritefrom the default tool list. Retain only the read-oriented tools required for static review:yaml tools: - read - glob - grep - If Git inspection requires command execution, expose only narrowly allowlisted, read-only operations such as
git diff,git show, andgit status. - Prohibit shell interpretation, command chaining, redirection, substitutions, and arbitrary executable paths.
- Require explicit user confirmation before any command execution or filesystem modification.
- If report creation requires
write, restrict it to a dedicated output directory and prevent overwriting existing source or configuration files. - Constrain all file access to the repository root after canonicalizing paths and rejecting traversal, symlink escapes, and absolute paths outside the workspace.
- Treat source code, comments, diffs, and repository documentation as untrusted data rather than agent instructions.
- Run the skill in a sandbox with minimal operating-system permissions, no unnecessary credentials, and no network access unless explicitly required.
- Remove
