T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:20- Finding
Excessive Tool Permissions for Underspecified Financial Operations
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20–23; supporting behavior at lines 44–48 and 247–251
Vulnerability Type: Excessive system permissions and insecure skill configuration
Risk Level: HighVulnerable Code Snippet
yaml tools: - read - exec - writeThe requested permissions are combined with instructions to perform financial operations:
text 1. **Add liquidity** — Find the best pool, recommend a range, handle approvals, deposit tokens 2. **Remove liquidity** — Withdraw tokens from an existing position (partial or full) 3. **Collect fees** — Claim accumulated trading fees from a position Each action delegates to the `liquidity-manager` agent for execution, with optional `pool-researcher` delegation for intelligent pool selection.The skill also advertises generic filesystem and command-execution functionality:
text - **文件处理**: 支持多种文件格式的读取、解析和写入操作 - **API集成**: 通过标准化接口调用外部服务并处理响应 - **命令执行**: 在安全沙箱中执行系统命令并收集结果 - **信息检索**: 快速搜索和过滤目标数据Technical Analysis
The skill requests broad
read,write, andexeccapabilities even though its declared purpose is managing Uniswap liquidity. The package contains onlySKILL.md; it provides no implementation that constrains accessible files, permitted commands, external endpoints, blockchain networks, smart-contract addresses, token approvals, or delegated agents.The document states that commands should be allowlisted, but this is advisory text rather than an enforceable control. It also promises to handle token approvals, deposits, withdrawals, and fee collection without defining mandatory safeguards such as:
- Explicit user confirmation immediately before signing.
- Chain ID and canonical contract allowlists.
- Token and pool contract verification.
- Approval amount and duration limits.
- Slippage, deadline, and transaction-value limits.
- Transaction simulation ...[truncated 2773 chars]
- Remediation
View remediation
Remediation Suggestions
-
Apply least privilege
- Remove
read,write, andexecunless each capability is essential. - Replace generic tools with a narrowly scoped, audited Uniswap or wallet interface.
- If filesystem access is required, restrict it to explicit project paths and deny credential, wallet, SSH, and environment files.
- Remove
-
Constrain command execution
- Prefer structured APIs over shell commands.
- If
execremains necessary, implement an enforceable command and argument allowlist. - Reject shell metacharacters, command substitution, pipes, redirection, dynamic executable paths, and unsanitized user input.
- Run commands in a sandbox with no unnecessary network access and minimal filesystem permissions.
-
Establish transaction safety gates
- Allowlist supported chain IDs, canonical Uniswap deployments, routers, position managers, and permit contracts.
- Verify token and pool addresses independently rather than trusting names or user-supplied metadata.
- Simulate every transaction and reject unexpected transfers, approvals, delegate calls, or contract creation.
- Decode and show the destination, method, parameters, token amounts, native value, gas estimate, slippage, deadline, and expected balance changes.
- Require explicit user confirmation immediately before each signature or transaction submission.
-
Limit token approvals and financial exposure
- Default to exact-amount approvals rather than unlimited approvals.
- Set configurable maximum transaction values, approval amounts, slippage, deadlines, and price-impact thresholds.
- Revoke temporary approvals where technically appropriate.
- Never request private keys or seed phrases; signing must remain inside a trusted wallet boundary.
-
Secure delegation
- Include or precisely identify the
liquidity-managerandpool-researchercomponents. - Pin their versio ...[truncated 639 chars]
- Include or precisely identify the
-
