T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:35- Finding
Search Skill Requests Unnecessary Filesystem and Command-Execution Privileges
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:35-39
Vulnerability Type: Excessive tool permissions and violation of least privilege
Risk Level: MediumVulnerable Code
yaml tools: - read - exec - glob - grepTechnical Analysis
The Skill's declared purpose is to submit queries to public search engines and aggregate search results. This functionality requires narrowly scoped outbound HTTPS access, but it does not inherently require arbitrary command execution or general access to the local filesystem.
The
execcapability permits system-command execution, whileread,glob, andgrepallow discovery and inspection of local files. These permissions exceed the minimum privileges required for web search. The documentation further advertises generic file processing and command execution atSKILL.md:238-240, and advises running with administrator privileges when permissions are insufficient atSKILL.md:275. These instructions unnecessarily increase the potential effect of misuse.The Markdown file does not contain an explicit malicious command, automatic credential theft, or a direct mechanism that executes a remote payload. The vulnerability is therefore an overprivileged capability declaration rather than evidence of intentional malware.
The network examples at
SKILL.md:155andSKILL.md:167submit search queries to Google and DuckDuckGo. Sending query text to a selected search provider is necessary for the declared functionality, and no confirmed API-key exfiltration path was identified. Nevertheless, users could place confidential information in a query, so query transmission should be disclosed and constrained.Attack Path
- A user installs or loads the Skill on an Agent platform that grants the tools declared in
SKILL.md. - The Agent receives
read,glob,grep, andexecauthority even though only network retrieval is needed for search. - An attacker ...[truncated 1452 chars]
- A user installs or loads the Skill on an Agent platform that grants the tools declared in
- Remediation
View remediation
Remediation Suggestions
- Remove
exec,read,glob, andgrepfrom the declared tools unless a concrete, documented search feature requires each capability. - Grant only a narrowly scoped HTTPS-fetching tool with an allowlist of supported search-engine domains.
- Remove the generic file-processing and command-execution claims at
SKILL.md:238-240. - Remove the administrator-execution recommendation at
SKILL.md:275. The Skill should fail safely when permissions are insufficient rather than request elevation. - Require explicit user confirmation before sending each query to an external provider, particularly when a query may contain personal, proprietary, or credential-like data.
- URL-encode query parameters and validate the selected engine against a fixed allowlist. Do not permit arbitrary schemes, hosts, redirects, or user-supplied executable commands.
- Document exactly which external providers receive query content and establish a policy that prohibits submitting secrets, API keys, private file contents, or authentication material.
- If local caching is later introduced, use a dedicated application directory with restrictive permissions and avoid storing raw sensitive queries.
- Enforce host-side sandboxing, deny shell access by default, and run the Agent under an unprivileged operating-system account.
- Remove
