JAVA.SV.LLM.TOOL.PRIV
Privileged LLM tool action without an authorization check
The JAVA.SV.LLM.TOOL.PRIV checker identifies privileged or destructive LLM tool actions that do not enforce an authorization check.
Vulnerability and risk
An LLM tool that can perform a privileged or destructive action without an authorization check can let the model exceed the permissions intended for the current user.
Mitigation and prevention
Require an authorization check before an LLM can invoke a privileged or destructive tool.
Vulnerable code example
Copy
import dev.langchain4j.agent.tool.Tool;
public class AccountTools {
private final UserAdminService userAdminService;
public AccountTools(UserAdminService userAdminService) {
this.userAdminService = userAdminService;
}
@Tool("Delete a user account")
public void deleteUser(String accountId) {
userAdminService.deleteAccount(accountId); // destructive action with no authorization check
}
}
Fixed code example
Copy
import dev.langchain4j.agent.tool.Tool;
public class AccountTools {
private final AuthorizationService authorizationService;
private final UserAdminService userAdminService;
public AccountTools(AuthorizationService authorizationService, UserAdminService userAdminService) {
this.authorizationService = authorizationService;
this.userAdminService = userAdminService;
}
@Tool("Delete a user account")
public void deleteUser(String accountId, UserPrincipal principal) {
authorizationService.requirePermission(principal, "accounts:delete");
userAdminService.deleteAccount(accountId);
}
}
External guidance
Security training
Application security training materials provided by Secure Code Warrior.