T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:10- Finding
Overprivileged Tool Access and Unsafe Privilege-Elevation Guidance
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Java guidance skill is not clearly malicious, but it requests broad read, write, and command-execution authority without enough limits or user-control guidance.
Review before installing. Use it only in a constrained Java project workspace, require confirmation before command execution, file modification, or external callbacks, avoid providing sensitive code or secrets, and do not run the agent as administrator just to satisfy this skill.
SKILL.md:10Overprivileged Tool Access and Unsafe Privilege-Elevation Guidance
The invocation description is broad enough to match generic coding, debugging, testing, and deployment requests, causing the skill to activate in many contexts beyond robust Java guidance. Because the skill also has read/exec/write capabilities, overbroad routing increases the chance that powerful actions are taken in situations where a narrower, safer skill would be more appropriate.
The Markdown advertises file writing, external API integration, information retrieval, and command execution without clear warnings about side effects, data exposure, or approval requirements. In an agent environment, this can normalize impactful operations and lead users or orchestrators to permit actions that alter the system, contact external services, or leak sensitive data.
The file states that commands run in a 'safe sandbox' but defines no actual sandbox boundaries, restrictions, or enforcement mechanism. This can create false trust and encourage execution of risky operations under the assumption they are contained when they may not be.
The skill documentation claims the skill is pure Markdown/natural-language driven, while the manifest declares both exec and write capabilities. This mismatch can mislead users and higher-level agents into treating the skill as low-risk documentation when it can actually modify files and execute commands, increasing the chance of unintended or unsafe actions.
No suspicious patterns detected.