T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:20- Finding
Overprivileged Tool Declaration for a Logo-Generation Skill
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20-23
Vulnerability Type: Excessive filesystem and command-execution permissions
Risk Level: MediumVulnerable Code
yaml tools: - read - exec - writeTechnical Analysis
The skill declares unrestricted reading, writing, and command-execution tools even though its stated primary purpose is to develop logo prompts and guide image generation. In particular, the
execcapability is not required by the documented prompt-generation workflow.Granting these capabilities violates the principle of least privilege. If the hosting agent authorizes tools according to this manifest, the skill receives access to operating-system commands and local files beyond the minimum access necessary for its stated purpose.
The document contains no executable scripts, malicious commands, remote payload retrieval, persistence behavior, or explicit data-exfiltration instructions. Therefore, this finding concerns the exposed privilege boundary rather than evidence that the skill currently exercises those permissions maliciously.
Attack Path
- A user loads or invokes the logo-generation skill.
- The hosting platform grants the declared
read,write, andexectools. - Attacker-controlled or untrusted content is introduced through a logo request, copied design brief, external model response, or later modification to the skill instructions.
- The agent is induced to invoke one of the unnecessarily available tools.
- Subject to the agent sandbox and operating-system permissions, commands could be executed or local files could be inspected or modified.
This attack path is conditional: the audited file does not itself contain instructions that perform these actions. Exploitation requires an additional prompt-injection source, malicious modification, or unsafe agent behavior.
Impact Assessment
Potential impact depends on the host platform's ...[truncated 697 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
execbecause the documented logo prompt-generation workflow does not require operating-system command execution. - Remove
readandwriteunless the skill implements a specific, documented file import or export operation. - If file access is required, restrict it to explicit user-selected input files and a dedicated output directory.
- Require interactive user approval before any file write, external API request, or command execution.
- Run image-generation integrations through a narrowly scoped API tool rather than a general-purpose shell.
- Apply filesystem, process, and network sandboxing at the host level; do not rely solely on skill instructions.
- Document each required capability, its allowed targets, and its expected operation so reviewers can verify that the manifest follows least privilege.
- Add tests that reject undeclared paths, shell metacharacters, arbitrary executable names, and attempts to access credentials or unrelated project files.
- Remove
