Security audit
line-oa-vnc-auth
Security checks for vulnerabilities and agentic risk
Overview
This skill provides a disclosed, temporary remote-browser login flow for LINE Official Account work, with clear user controls and teardown requirements.
Install only if you need a temporary user-operated browser session for LINE Official Account login or MFA. Treat the noVNC URL and VNC password as sensitive, verify the tunnel and VNC processes are closed after use, and decide explicitly whether the isolated browser profile should retain a LINE session.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
