T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:12- Finding
Excessive Agent Capabilities and Unsafe Privilege-Elevation Guidance
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This logo-design skill is not clearly malicious, but it asks for broad file and command authority that is not well scoped to brand-design output.
Review before installing. Use it only in a sandboxed workspace, avoid administrator privileges, do not provide sensitive brand or credential data, and require explicit confirmation before it reads files, writes outputs, calls external services, or runs any command.
SKILL.md:12Excessive Agent Capabilities and Unsafe Privilege-Elevation Guidance
The skill declares exec alongside read and write even though its stated purpose is logo and brand identity generation. This unnecessarily grants command-execution capability to a content-generation skill, increasing the chance that user-controlled prompts or future skill logic could invoke shell commands, access local resources, or pivot into broader system actions.
The invocation wording is broad enough that an agent may activate the skill from loosely related conversation context rather than an explicit user request. Unintended activation becomes more dangerous here because the skill advertises read/write/exec-adjacent behavior elsewhere, so accidental routing could expose data or trigger side effects beyond simple design generation.
The manifest and top-level description present a narrow brand-design skill, but later sections expand it into generic file processing, API integration, and system command execution. This scope drift is dangerous because operators may authorize the skill based on a benign design use case while the documentation normalizes much broader capabilities that could be abused for data access, exfiltration, or arbitrary automation.
The displayName is set to a Chinese term ('驱动') even though the rest of the file is mixed-language and there is no indication of user language preference or locale selection. This can violate language/locale policy expectations when a skill presents a fixed language choice without opt-in.
The file promises structured brand-identity outputs, but elsewhere frames the skill as a generic automation driver with broader operational features. This inconsistency can mislead users and reviewers about the true trust boundary, making it easier for high-risk capabilities to hide behind an apparently harmless design workflow.
Colloquial follow-up phrases such as casual refinement requests are too generic and could be interpreted as implicit triggers for the skill outside a deliberate brand-design workflow. On their own they are low severity, but in combination with the skill's broadened capabilities they increase the chance of accidental invocation and confusing agent behavior.
No suspicious patterns detected.