T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:14- Finding
Overprivileged Tool Permissions Without a Verifiable Implementation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14-17; credential and execution workflow at lines 91-95
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: MediumVulnerable Code
yaml tools: - read - exec - writeThe workflow subsequently instructs the agent to verify a credential file, execute
filter.js, and edit itsisSpam()function. However, the audited package contains onlySKILL.md; the referenced script is not included.Technical Analysis
The Skill declares unrestricted file-reading, file-writing, and command-execution capabilities. These privileges exceed what can be justified from the package's auditable contents because no executable filtering implementation is supplied.
The documented workflow also directs the agent toward
./.config/platform/credentials.json, which is expected to contain a valid API key. Becausefilter.jsis absent, reviewers cannot verify how that script would use, transmit, store, or log the credential. If an unrelated or attacker-controlledfilter.jsis present in the working directory, the documented command could execute it with the agent's ambient permissions and access to sensitive credentials.This is a least-privilege failure and an unsafe trust-boundary design. The audit found no explicit instruction to disclose the API key and no bundled malicious script, so the evidence supports an overprivileged and suspicious configuration rather than confirmed credential exfiltration.
Attack Path
- An agent loads the Skill and grants its declared
read,write, andexeccapabilities. - Following the documented workflow, the agent checks the local credential file containing the platform API key.
- The agent invokes
node filter.js scan ...ornode filter.js feed .... - Because the audited package does not supply
filter.js, command resolution depends on an externally supplied file in the cu ...[truncated 916 chars]
- An agent loads the Skill and grants its declared
- Remediation
View remediation
Remediation Suggestions
- Include the referenced
filter.jsimplementation in the package so its command execution, network destinations, input handling, and credential handling can be audited. - Remove
writepermission unless the Skill has a concrete, documented need to modify files. Rule customization should preferably occur through a constrained configuration file rather than arbitrary source-code editing. - Restrict
readpermission to explicit feed inputs and configuration paths. Do not instruct the agent to open or display raw credential files. - Obtain credentials through a platform secret provider or a narrowly scoped environment variable and ensure they are never printed, logged, embedded in command arguments, or written to generated output.
- Restrict execution to a packaged, integrity-verified script using an absolute or package-relative path rather than resolving
filter.jsfrom an uncontrolled working directory. - Document and allowlist the exact remote API host, permitted HTTP methods, and required API-key scope.
- Validate subcommunity names and other user-controlled arguments before passing them to commands or network requests.
- Run the implementation in a sandbox with a read-only project filesystem, limited network access, no access to unrelated user files, and a minimally privileged API key.
- Include the referenced
