T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:21- Finding
Excessive and Unrestricted Agent Tool Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 21-24
Vulnerability Type: Excessive read, write, and command-execution permissions
Risk Level: MediumVulnerable Code
yaml tools: - read - exec - writeThe declared capabilities are also described at
SKILL.md, lines 261-264, as supporting file reading and writing, external API integration, and system-command execution.Technical Analysis
The Skill requests general-purpose
read,write, andexectools without specifying restrictions on accessible paths, permitted commands, command arguments, network destinations, or destructive actions. The documented purpose is primarily to provide configuration and development guidance for the magic-api framework, so unrestricted command execution and filesystem modification exceed the minimum permissions clearly required by the stated task.Declaring a tool does not independently prove malicious execution. However, making unrestricted privileged tools available creates an exploitable least-privilege failure: ambiguous input, unsafe generated instructions, or malicious content processed by the Skill could cause the Agent to access unrelated files or execute commands outside the intended project scope.
Attack Path
- A user activates the Skill for API generation or configuration.
- The Agent grants the Skill access to the declared
read,write, andexectools. - Attacker-controlled or ambiguous input causes generated instructions to reference an arbitrary path or shell command.
- The Agent reads sensitive local files, modifies files outside the project, or executes an unintended command.
- If outbound API access is also available, information obtained through file access or command output could be sent to an unspecified external service.
Impact Assessment
Successful exploitation could provide access to any files and commands permitted by the host Agent's execution cont ...[truncated 434 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
execandwriteif the Skill only needs to provide documentation or generated text. - Replace unrestricted access with narrowly scoped tools that operate only within the current project directory.
- Allowlist necessary commands, executable paths, arguments, file extensions, and network destinations.
- Reject absolute paths, parent-directory traversal, shell metacharacters, and untrusted command interpolation.
- Require explicit user confirmation before overwriting files, deleting data, executing commands, or sending data to external services.
- Run permitted commands in an isolated sandbox with minimal filesystem access, no inherited secrets, restricted networking, and resource limits.
- Document the exact operations for which each privileged tool is required.
- Remove
