T09 · Insecure Skill Coding Practices
- Location
SKILL.md:15- Finding
LINE Authentication Tokens Stored in a Plaintext JSON File
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent LINE client, but it gives an agent broad access to private messages, contacts, groups, profile settings, and session tokens without enough user-control or credential-protection guidance.
Install only if you intentionally want an agent to operate your LINE account. Treat ~/.line-client/tokens.json and ~/.line-client/sqr_cert as secrets, restrict their permissions, avoid sharing logs or prompts that expose them, and require explicit confirmation before reading messages, sending/unsending messages, changing contacts/groups, issuing tokens, or modifying profile/settings.
SKILL.md:15LINE Authentication Tokens Stored in a Plaintext JSON File
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## HMAC Signing
All API calls require `X-Hmac` header. The WASM signer handles this automatically:
- Derives key from version "3.7.1" + access token via proprietary KDF (in lstm.wasm)
- Signs `path + body` → base64 → `X-Hmac`
- Server mode: ~13ms/sign (Node.js HTTP server on port 18944, auto-started)
- Subprocess mode: ~2s/sign (fallback)
The skill description is broad enough to match many generic LINE-related requests without clearly constraining when user consent, account ownership, or high-risk actions are required. Because this skill can read messages, send messages, and modify account state, over-broad invocation increases the chance of unintended activation for privacy-sensitive or destructive operations.
The documentation explicitly identifies token and certificate storage locations but does not warn that these artifacts are equivalent to session credentials and should be protected as secrets. In a skill context, this materially lowers the barrier to credential theft or misuse by downstream agents or users who may treat these files as ordinary cache data.
The skill advertises extensive capabilities to read private messages, enumerate contacts, issue tokens, modify groups, unsend messages, and change account settings without prominent warnings or safety guardrails. In this context, lack of privacy and destructive-action warnings makes misuse more likely and increases the risk of unauthorized surveillance, impersonation, social graph harvesting, or account tampering.
No suspicious patterns detected.