Back to skill

Security audit

LINE 貼圖生成大師

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed LINE sticker planning and quality-check workflow; the release-related TODO is maintenance context, not hidden runtime behavior.

Installers should treat todo.md and release sections as maintainer notes, not normal sticker-generation steps. Use the skill for prompt/copy/image workflow guidance, and only run git, npm, or publishing commands after explicitly choosing to work on those related projects.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The todo list expands the skill beyond its stated LINE sticker-generation purpose into website integration, local sync, validation, GitHub push, and publishing workflows. This kind of scope drift is dangerous because an agent using the skill may be induced to perform repository modification and release-related actions that are not justified by the declared functionality, increasing the chance of unauthorized changes or unintended publication.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The ClawHub release checklist introduces account-dependent login checks, dry-run/version checks, formal publication, and post-release verification even though the skill is described as a sticker-production workflow. In context, these instructions could cause an agent to interact with authenticated release surfaces and publish artifacts publicly, which creates a materially higher risk of unauthorized deployment or account misuse.

Static analysis

No suspicious patterns detected.