Back to skill

Security audit

艺术

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly about a shared pixel-art board, but it uses broad automation scope, credential storage, public posting, and unspecified shell execution that should be reviewed before installation.

Install only if you are comfortable with a skill that can run shell commands, write local state, store bot credentials, and send messages or callbacks to external services. Verify the actual artboard.sh script source before use, keep credentials out of version control, avoid sensitive chat content, and do not run this skill or its scripts with administrator/root privileges.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:305
Finding

Unnecessary Administrator Execution Guidance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description includes a broad invocation cue suggesting use for general AI calling, agent orchestration, and LLM applications, which is far wider than the skill's stated purpose of interacting with a collaborative art board. Overbroad routing language can cause the skill to be invoked in unrelated contexts, unnecessarily exposing exec, file write, and networked behaviors where they are not needed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The display name and large portions of the manifest/instructions are presented in Chinese, with no indication that the user can choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is justified, which is not documented here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill documents chat and callback URL features that transmit user-provided content to external services, but it lacks a clear privacy warning about what data may leave the local environment. Because the skill also supports agent-generated messages and asynchronous callbacks, users may unknowingly send sensitive prompts, identifiers, or workspace context to third-party endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow notes that registration saves credentials locally, but it does not present this as a prominent warning with storage location, sensitivity, retention, or permission guidance. In a skill that uses local files plus command execution, hidden or understated credential persistence increases the chance of accidental disclosure through logs, backups, workspace sync, or version control.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill advertises an exec capability and includes shell command workflows, but the security section claims only whitelisted commands are executed without documenting or demonstrating any actual whitelist enforcement. This mismatch can mislead users or agents into assuming command execution is constrained when it is effectively general-purpose, increasing the risk of unsafe shell execution if inputs are ever derived from user or model output.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The document claims outputs will not expose secrets, yet the workflow explicitly stores bot credentials and tokens in local config files and uses them for subsequent API operations. Without a clear boundary on what may be logged, printed, or copied from those files, the documentation gives a false sense of secrecy hygiene and could lead to inadvertent credential disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.