T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:305- Finding
Unnecessary Administrator Execution Guidance
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly about a shared pixel-art board, but it uses broad automation scope, credential storage, public posting, and unspecified shell execution that should be reviewed before installation.
Install only if you are comfortable with a skill that can run shell commands, write local state, store bot credentials, and send messages or callbacks to external services. Verify the actual artboard.sh script source before use, keep credentials out of version control, avoid sensitive chat content, and do not run this skill or its scripts with administrator/root privileges.
SKILL.md:305Unnecessary Administrator Execution Guidance
The description includes a broad invocation cue suggesting use for general AI calling, agent orchestration, and LLM applications, which is far wider than the skill's stated purpose of interacting with a collaborative art board. Overbroad routing language can cause the skill to be invoked in unrelated contexts, unnecessarily exposing exec, file write, and networked behaviors where they are not needed.
The display name and large portions of the manifest/instructions are presented in Chinese, with no indication that the user can choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is justified, which is not documented here.
The skill documents chat and callback URL features that transmit user-provided content to external services, but it lacks a clear privacy warning about what data may leave the local environment. Because the skill also supports agent-generated messages and asynchronous callbacks, users may unknowingly send sensitive prompts, identifiers, or workspace context to third-party endpoints.
The workflow notes that registration saves credentials locally, but it does not present this as a prominent warning with storage location, sensitivity, retention, or permission guidance. In a skill that uses local files plus command execution, hidden or understated credential persistence increases the chance of accidental disclosure through logs, backups, workspace sync, or version control.
The skill advertises an exec capability and includes shell command workflows, but the security section claims only whitelisted commands are executed without documenting or demonstrating any actual whitelist enforcement. This mismatch can mislead users or agents into assuming command execution is constrained when it is effectively general-purpose, increasing the risk of unsafe shell execution if inputs are ever derived from user or model output.
The document claims outputs will not expose secrets, yet the workflow explicitly stores bot credentials and tokens in local config files and uses them for subsequent API operations. Without a clear boundary on what may be logged, printed, or copied from those files, the documentation gives a false sense of secrecy hygiene and could lead to inadvertent credential disclosure.
No suspicious patterns detected.