T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:22- Finding
Unnecessary Shell Execution Capability Violates Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 22–24
Vulnerability Type: Excessive tool permissions
Risk Level: MediumEvidence
yaml tools: - read - execThe declared capability conflicts with the Skill's own statements at lines 437–439:
markdown ### 可用性分类 - **分类**:MD(纯 Markdown 指令,无需 exec) - **说明**:基于 Markdown 的 AI Skill,完全通过自然语言指令驱动 Agent 执行效率管理任务。所有记忆与计划通过文件读写管理,无需命令行执行能力。The latter passage states that this is a pure Markdown Skill and that command-line execution is unnecessary.
Technical Analysis
The Skill requests the general-purpose
exectool despite documenting a workflow that only needs local Markdown file operations. Shell execution can provide substantially broader access than the productivity-management functionality requires, including access to host files, processes, environment variables, and executable programs within the Agent runtime's operating-system permissions.Merely declaring
execdoes not prove that the Skill currently executes malicious commands. However, retaining an unnecessary high-impact capability violates least privilege and enlarges the consequences of malicious, misleading, or otherwise untrusted instructions processed while the Skill is active.Attack Path
- The Agent loads the Skill and makes its declared
execcapability available. - The Agent processes attacker-controlled or misleading content during a productivity task, such as a task description copied from an untrusted source.
- That content induces the Agent to invoke a shell command under the pretext of organizing or processing the user's files.
- Because
execis unnecessarily available, the command runs with the permissions of the Agent process. - Depending on runtime sandboxing and operating-system permissions, the command could inspect unrelated files, access environment data, alter local content, or launch additional processes.
This is a capabi ...[truncated 873 chars]
- The Agent loads the Skill and makes its declared
- Remediation
View remediation
Remediation Suggestions
-
Remove
execfrom the declared tools:yaml tools: - read -
If the Skill must create and update productivity records, declare a dedicated file-write capability rather than general shell execution.
-
Restrict file operations to a canonicalized
~/productivity/directory and reject path traversal, symbolic-link escapes, and writes outside that boundary. -
Require explicit user confirmation before creating the initial directory structure, overwriting files, deleting tasks, or moving records.
-
Keep preference persistence opt-in, consistent with the approval requirement documented at lines 302–303.
-
Add automated metadata validation that rejects unnecessary high-risk capabilities when the Skill documentation states that they are not required.
-
If
execmust be retained for an undocumented use case, document that use case, allowlist exact commands and arguments, run them in a sandbox, and require confirmation before execution.
-
