T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:36- Finding
Unnecessary Command-Execution Permission Violates Least Privilege
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 36-38
Vulnerability Type: Excessive tool permissions
Risk Level: MediumVulnerable Code
yaml tools: - read - execThe declared permissions conflict with the Skill's own description at lines 206-208:
markdown ### 可用性分类 - **分类**:MD(纯Markdown指令) - **说明**:极简入门skill,通过自然语言指令驱动Agent辅助用户在无代码平台搭建最小工作流Technical Analysis
The Skill declares access to the
exectool even though its documented functionality consists entirely of static Markdown guidance for designing no-code workflows. No instruction in the reviewed file requires local command execution. Local file-reading access also appears unnecessary for the stated functionality.Granting command-execution capability beyond legitimate operational requirements violates the principle of least privilege. Although the reviewed Skill contains no malicious command, script, or direct instruction to invoke
exec, the excessive capability increases the consequences of future modification, compromised surrounding context, or instruction injection. An attacker-controlled instruction interpreted while the Skill is active could attempt to use the already-authorized execution tool.Attack Path
- An agent loads the Skill and grants the tools declared in its front matter, including
exec. - The agent subsequently processes attacker-controlled or compromised instructions in the same operational context.
- Those instructions induce the agent to invoke
exec, despite command execution not being required by the Skill's intended function. - Commands execute with the operating-system privileges and environmental access available to the hosting agent.
- The resulting impact depends on sandboxing, approval controls, filesystem permissions, network restrictions, and the privileges of the agent process.
This is a conditional exposure rather than evidence that the current Skill itself ...[truncated 685 chars]
- An agent loads the Skill and grants the tools declared in its front matter, including
- Remediation
View remediation
Remediation Suggestions
- Remove
execfrom thetoolsdeclaration because no documented feature requires command execution. - Remove
readas well unless the Skill is intentionally extended with a narrowly defined local-file operation. - Declare no tools for this Markdown-only educational Skill.
- If command execution becomes necessary in a future release, document the exact commands and operational purpose, use an explicit allowlist, require user confirmation, and run commands in a restricted sandbox.
- Apply filesystem, network, environment-variable, and process-level restrictions to any execution tool exposed by the hosting agent.
- Add a release review that compares declared tools against actual functionality and rejects permissions that lack a concrete use case.
- Remove
