Link Search Menu Expand Document

Weak Isolation Vulnerability in Agentic Coding

Play SecureFlag Play Agentic Coding Labs on this vulnerability with SecureFlag!

  1. Weak Isolation Vulnerability in Agentic Coding
    1. Description
    2. Impact
    3. Scenarios
    4. Prevention
    5. References

Description

Most skill platforms run whatever a skill asks for directly on the host machine. The skill has access to the same filesystem, network, and process space as the developer’s other work. Container or sandbox isolation, when it exists at all, is usually an opt-in feature rather than the default.

Weak Isolation is the risk that comes from that default. A skill does not need to be sophisticated to do damage if nothing stands between it and the host. One assessment of a popular assistant platform found over 135,000 publicly exposed instances running in this unisolated mode, and described the setup plainly as untrusted code execution with persistent credentials, unsuitable for an ordinary workstation.

Impact

Without isolation, a skill’s blast radius is the whole machine rather than a contained slice of it. A compromised or malicious skill can read any file the user can read, reach any network destination the machine can reach, and see every other process running alongside it, including other skills and whatever credentials they happen to be holding.

Scenarios

A team runs an assistant configured the default way, with no container boundary around skill execution. A skill installed for one project reads an SSH key left over from an unrelated project on the same machine, and uses it to reach a server that skill was never supposed to know about. Nothing in the setup prevented it, because nothing was isolated to begin with.

Prevention

If you install and use skills, do not assume isolation exists just because the platform could support it. Check whether skill execution actually runs in a container or sandbox, and if the option is there but disabled, turn it on rather than leaving it as an opt-in nobody opted into.

If you build or operate the platform that runs skills, make containment the default rather than a feature.

  • Default to contained execution: Run every skill in a container or sandbox with no access to the rest of the host, and require an explicit, logged decision to run anything in host mode.
  • Scope what a contained skill can reach: Give each skill its own filesystem view, its own credentials, and an explicit network allowlist, so that a compromise stays inside the boundary it happened in.

References

OWASP - Agentic Skills Top 10

OWASP - TOP 10 for Agentic Applications