T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:24- Finding
Excessive Execution and File-Write Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24-27
Vulnerability Type: Excessive tool permissions violating least privilege
Risk Level: MediumComplete Code Snippet:
yaml tools: - read - exec - writeTechnical Analysis
The skill declares
execandwritecapabilities even though its documented purpose is to review JavaScript source code and return recommendations or generated code. No documented workflow requires shell-command execution or filesystem modification.These unnecessary capabilities increase the consequences of malicious, adversarial, or misinterpreted input. If the hosting agent grants the declared tools without an additional authorization boundary, attacker-controlled content submitted for review could influence the agent into executing commands or changing files. No explicit malicious command or automatic exploitation behavior was found in the audited file; the risk arises from the excessive permission configuration.
Attack Path
- The skill is loaded by an agent that grants its declared
execandwritetools. - An attacker supplies JavaScript or accompanying review instructions containing adversarial content.
- The content attempts to persuade or confuse the agent into treating shell execution or file modification as part of the review.
- Because the skill possesses permissions beyond those needed for analysis, the agent may invoke
execorwrite. - Commands could run with the agent process's operating-system privileges, or files accessible to that process could be modified.
Exploitation depends on the hosting agent allowing tool use and failing to require independent authorization or enforce command and path restrictions.
Impact Assessment
Successful exploitation could permit command execution with the privileges of the agent process and modification of files writable by that process. The scope may include the current workspace ...[truncated 299 chars]
- The skill is loaded by an agent that grants its declared
- Remediation
View remediation
Remediation Suggestions
- Remove
execandwritefrom the declared tool list; retain onlyreadif repository inspection is required. - If future functionality legitimately needs file changes, require explicit user confirmation for each write and constrain writes to an approved workspace.
- If execution is later required, use a sandbox with a strict command allowlist, limited filesystem access, no inherited secrets, restricted network access, resource limits, and a non-privileged operating-system identity.
- Treat reviewed source code and user-supplied instructions as untrusted data rather than executable agent directives.
- Record and expose all command and file-modification operations for user review.
- Remove
