T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:122- Finding
Instruction to Bypass Enterprise Feature Authorization Controls
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 122-131
Vulnerability Type: Authorization and entitlement-control bypass guidance
Risk Level: MediumVulnerable Content
text | ERR_ENTERPRISE_IS_BLOCKED | Enterprise feature locked | The enterprise block must be removed (modify the enterprise-checking logic in biz_service) | ## Enterprise Lock Mode Some features in Teamgram Community Edition are blocked by an enterprise-edition lock, manifested as: - `ERR_ENTERPRISE_IS_BLOCKED` errors - Interception through the `checkEnterprise()` function in a helper at the biz_service layer Unlock method: Modify the enterprise-checking logic in the corresponding biz_service helper and remove or bypass the `checkEnterprise()` call.The snippet above is an English translation of the audited file's Chinese text.
Technical Analysis
The skill explicitly instructs users or agents to remove or bypass the server-side
checkEnterprise()control. This check is described as enforcing the boundary between community and enterprise functionality. Disabling it would circumvent an intended authorization or entitlement decision rather than diagnosing the cause of the error through an approved configuration or licensing process.This guidance is also inconsistent with the skill's declared documentation-only purpose. Although the package contains no executable code and cannot perform the bypass by itself, an agent following the instructions could modify the referenced server implementation and eliminate the control.
Attack Path
- A developer or coding agent loads the skill while troubleshooting
ERR_ENTERPRISE_IS_BLOCKED. - The skill identifies
checkEnterprise()in thebiz_servicelayer as the enforcement point. - The developer or agent locates the corresponding helper in a Teamgram Server checkout.
- Following the skill's instruction, they remove the call, bypass its result, or modify it to alwa ...[truncated 952 chars]
- A developer or coding agent loads the skill while troubleshooting
- Remediation
View remediation
Remediation Suggestions
- Remove all instructions recommending removal, bypass, or forced success of
checkEnterprise(). - Replace the “unlock method” with approved remediation paths, such as obtaining the required enterprise entitlement, verifying license configuration, or contacting the project vendor or maintainers.
- Retain diagnostic information only at a descriptive level: explain that the error originates from an enterprise feature gate without directing users to defeat it.
- If source-level debugging is necessary, instruct developers to confirm that the check is operating as designed and to preserve fail-closed behavior.
- Document supported community-edition alternatives for unavailable functionality where applicable.
- Add an explicit safety note that authorization, licensing, and entitlement checks must not be disabled without documented approval from the system owner and applicable rights holder.
- Remove all instructions recommending removal, bypass, or forced success of
