Back to skill

Security audit

Line Client

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent LINE client, but it gives an agent broad access to private messages, contacts, groups, profile settings, and session tokens without enough user-control or credential-protection guidance.

Install only if you intentionally want an agent to operate your LINE account. Treat ~/.line-client/tokens.json and ~/.line-client/sqr_cert as secrets, restrict their permissions, avoid sharing logs or prompts that expose them, and require explicit confirmation before reading messages, sending/unsending messages, changing contacts/groups, issuing tokens, or modifying profile/settings.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:15
Finding

LINE Authentication Tokens Stored in a Plaintext JSON File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 186)May include surrounding context.

md
## HMAC Signing

All API calls require `X-Hmac` header. The WASM signer handles this automatically:
- Derives key from version "3.7.1" + access token via proprietary KDF (in lstm.wasm)
- Signs `path + body` → base64 → `X-Hmac`
- Server mode: ~13ms/sign (Node.js HTTP server on port 18944, auto-started)
- Subprocess mode: ~2s/sign (fallback)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill description is broad enough to match many generic LINE-related requests without clearly constraining when user consent, account ownership, or high-risk actions are required. Because this skill can read messages, send messages, and modify account state, over-broad invocation increases the chance of unintended activation for privacy-sensitive or destructive operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly identifies token and certificate storage locations but does not warn that these artifacts are equivalent to session credentials and should be protected as secrets. In a skill context, this materially lowers the barrier to credential theft or misuse by downstream agents or users who may treat these files as ordinary cache data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises extensive capabilities to read private messages, enumerate contacts, issue tokens, modify groups, unsend messages, and change account settings without prominent warnings or safety guardrails. In this context, lack of privacy and destructive-action warnings makes misuse more likely and increases the risk of unauthorized surveillance, impersonation, social graph harvesting, or account tampering.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.