T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:27- Finding
Excessive Local Tool Permissions Violate Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 27–31
Vulnerability Type: Excessive filesystem and command-execution permissions
Risk Level: MediumVulnerable Configuration
yaml tools: - read - exec - write - globTechnical Analysis
The skill declares unrestricted file reading, file writing, filesystem enumeration, and command-execution capabilities. Its documented primary purpose is managing forms through HTTPS API requests, so these local system capabilities exceed the permissions evidently required by the stated workflow.
In particular, combining
globandreadpermits discovery and retrieval of accessible local files, whilewritepermits their creation or modification. Theexeccapability can invoke local processes and substantially increases the consequences of unsafe, attacker-controlled, or incorrectly interpreted instructions.The documentation also recommends running with administrator privileges when file permissions are insufficient at
SKILL.md:393. Although this is not an automatic privilege-escalation mechanism, following that guidance would increase the scope of the excessive tool permissions.Attack Path
- A user loads the skill, making the declared
read,write,glob, andexectools available to the agent. - The agent processes attacker-controlled or otherwise untrusted form content, API data, or user instructions.
- Malicious content induces the agent to enumerate files with
glob, retrieve files withread, modify files withwrite, or invoke commands throughexec. - If the agent is running with elevated privileges, including after following the administrator guidance in the documentation, those operations inherit the broader access of the host process.
- Accessible local data may consequently be disclosed or altered, and commands may execute within the permissions and sandbox boundaries of the agent process.
This path ...[truncated 787 chars]
- A user loads the skill, making the declared
- Remediation
View remediation
Remediation Suggestions
- Remove
read,write, andglobunless a documented workflow demonstrably requires local file access. - Replace unrestricted
execwith a dedicated HTTPS client or narrowly scoped API tool restricted to the intended service and methods. - If command execution is unavoidable, enforce an argument-aware allowlist, prohibit shell interpretation, reject user-controlled command fragments, and apply strict time, resource, and output limits.
- Restrict filesystem access to an isolated workspace containing no credentials or unrelated user files.
- Run the skill as a dedicated, unprivileged operating-system identity inside a sandbox or container with a read-only root filesystem where possible.
- Remove the recommendation to run as administrator. Document the exact minimum filesystem and network permissions instead.
- Require explicit user confirmation before sensitive file operations or command execution, and log tool invocations without recording secrets.
- Validate and treat all user content, imported form data, and remote API responses as untrusted data rather than executable instructions.
- Remove
