T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:25- Finding
Excessive Agent Tool Permissions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 25–28
Vulnerability Type: Excessive tool permissions and violation of least privilege
Risk Level: Mediumyaml tools: - read - exec - writeTechnical Analysis
The skill requests
read,exec, andwritecapabilities, although its documented purpose is to manage Linear issues, projects, and team workflows. The file does not contain an implementation or documented workflow that requires arbitrary local command execution or filesystem modification.Declaring
execandwriteunnecessarily expands the skill's authority. If these permissions are granted by the hosting agent, untrusted task content or instruction injection could potentially induce the agent to execute local commands or alter files. The risk arises from excessive capability exposure rather than from an explicitly malicious command in the audited file.Attack Path
- The agent loads the skill and grants the tools declared in its metadata.
- The skill receives attacker-controlled task content, issue content, or other untrusted instructions.
- Malicious content persuades or instructs the agent to invoke
execorwrite. - The agent executes a local command or modifies a file under its operating-system identity.
- The resulting access is limited only by the permissions and sandbox controls applied to the agent process.
Impact Assessment
Successful exploitation could permit command execution and filesystem modification with the privileges of the agent process. Depending on the runtime environment, this could affect project files, accessible user files, local configuration, or credentials readable by that process.
No direct malicious command, persistence mechanism, remote payload retrieval, credential theft, or data-exfiltration behavior was found in the audited file. Exploitation therefore depends on the agent granting the declared capabilities and subsequentl ...[truncated 48 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
execandwritefrom the declared tool list unless a specific, documented operation requires them. - Use a narrowly scoped Linear API integration rather than general-purpose shell or filesystem capabilities.
- Grant read-only Linear permissions by default and require explicit user confirmation before creating or modifying issues, projects, or workflow state.
- If local execution is unavoidable, restrict commands through an allowlist, isolate execution in a sandbox, and deny access to credentials and unrelated files.
- Treat issue descriptions, project content, and other externally sourced text as untrusted data rather than executable instructions.
- Log sensitive tool invocations and clearly present the intended command or file modification to the user before execution.
- Remove
