T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:35- Finding
Unnecessary Arbitrary Command-Execution Permission
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 35–38
Vulnerability Type: Excessive tool permissions and violation of least privilege
Risk Level: MediumVulnerable Code
yaml tools: - read - exec - writeTechnical Analysis
The skill declares access to the unrestricted
exectool even though its documented functions are Markdown normalization, HTML-to-Markdown conversion, linting, and table-of-contents generation. These content-processing operations do not inherently require arbitrary system command execution.The package contains only
SKILL.mdand provides no implementation that justifies this permission, no command allowlist, no argument validation mechanism, and no constrained execution interface. Grantingexectherefore expands the skill's authority beyond its stated operational requirements and violates the principle of least privilege.The permission declaration is not itself proof that a malicious command will execute automatically. Exploitation depends on the hosting agent granting the requested tool and subsequently invoking it, such as after interpreting attacker-controlled document content as instructions.
Attack Path
- A user installs or loads the skill in an agent environment that grants the tools declared in
SKILL.md. - The agent receives attacker-controlled Markdown, HTML, or plain text for conversion or linting.
- The input contains instructions crafted to influence the agent into invoking a system command.
- Because the skill unnecessarily has access to
exec, the agent may issue the command rather than limiting its actions to in-memory content transformation. - The command executes with the operating-system and sandbox privileges available to the agent.
Impact Assessment
Successful exploitation could allow execution of arbitrary commands within the agent's security context. Depending on sandboxing, filesystem permissions, and available credentials, this may permit reading ...[truncated 399 chars]
- A user installs or loads the skill in an agent environment that grants the tools declared in
- Remediation
View remediation
Remediation Suggestions
- Remove
execfrom the declared tools:yaml tools: - read - write - For transformations performed entirely on supplied content, consider removing all tool permissions and returning the transformed Markdown directly.
- If filesystem processing is required, restrict
readandwriteto an explicit workspace directory and prevent path traversal or access to sensitive files. - If external lint execution is genuinely necessary, replace arbitrary
execaccess with a dedicated operation that invokes a fixed executable. - Use a strict argument array rather than shell-string construction, validate all options against an allowlist, and never interpolate document content into commands.
- Run any necessary formatter or linter in a sandbox with restricted filesystem, network, environment-variable, and process permissions.
- Require explicit user confirmation before executing commands and treat all Markdown, HTML, and plain-text input as untrusted data rather than agent instructions.
- Remove
