T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:30- Finding
Unnecessary Arbitrary Command-Execution Capability
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 30-34 and 141-143
Vulnerability Type: Excessive tool permissions
Risk Level: MediumVulnerable Configuration
yaml tools: - read - exec - writeThe skill is additionally classified as an execution-enabled Markdown skill:
markdown - **Category**: MD+execute()Technical Analysis
The skill is documented as a JSON parsing, cleaning, transformation, validation, and export utility. These functions may require file-reading and file-writing capabilities, but the document does not define a concrete operation that requires unrestricted command execution.
Declaring the
exectool gives the skill authority beyond its documented functional requirements and violates the principle of least privilege. This is particularly risky when the skill processes attacker-controlled JSON, text, Markdown, file paths, or processing instructions. If such input is interpreted as agent instructions rather than inert data, the unnecessary execution capability can provide a path from untrusted content to local command execution.The audited package contains no script implementing a direct command-injection payload. Exploitation therefore depends on the hosting agent allowing the skill to invoke its declared tools and on attacker-controlled content influencing tool selection or command arguments.
Attack Path
- A user loads the JSON-processing skill in an agent that grants the tools declared in
SKILL.md. - The agent grants the skill access to
read,write, andexec. - An attacker supplies crafted JSON, Markdown, processing instructions, or a malicious data file.
- The crafted content induces the agent to treat embedded instructions as operational directions.
- The agent invokes
exec, despite command execution not being necessary for JSON processing. - Commands run with the permissions of the agent process and can access res ...[truncated 627 chars]
- A user loads the JSON-processing skill in an agent that grants the tools declared in
- Remediation
View remediation
Remediation Suggestions
- Remove
execfrom the declared tool list unless a specific, indispensable command-execution use case is documented. - Change the skill classification from
MD+execute()to a non-executing skill classification. - Implement JSON processing through native, structured agent operations rather than shell commands.
- If execution is genuinely required, define a narrow allowlist of permitted executables and subcommands.
- Pass arguments as structured values rather than constructing shell command strings.
- Reject shell metacharacters and untrusted executable paths.
- Run permitted commands in a restricted sandbox with no network access and minimal filesystem access.
- Require explicit user confirmation before every execution request.
- Treat all processed JSON, text, and Markdown as untrusted data and prevent it from being interpreted as skill instructions.
- Remove
