T01 · Skill Instruction Hijacking
- Location
SKILL.md:164- Finding
Untrusted Discord Messages Can Trigger Broad Agent Actions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its automation purpose, but it gives externally triggered Discord tasks broad authority to run commands, mutate Linear/Git state, and use stored credentials without enough scoping or approval controls.
Review and tighten this skill before installing: require explicit mentions or approved users for Discord triggers, reject free-form task instructions from webhooks, require confirmation before exec, Linear changes, DMs, commits, or pushes, store tokens with owner-only permissions or a secret manager, and use least-privileged Linear and Git credentials.
SKILL.md:164Untrusted Discord Messages Can Trigger Broad Agent Actions
SKILL.md:70Linear API Key File Is Created Without Explicit Restrictive Permissions
The manifest claims risk code was removed and security improved, yet the skill still instructs shell execution, credential-based API use, external webhook automation, and automatic git push. Those capabilities are not inherently malicious, but the mismatch is dangerous because it can misrepresent operational risk and cause users or platforms to trust the skill more than warranted.
The trigger keywords are broad terms like 'processing', 'task', and 'automate', which can cause the skill to activate in contexts far outside the intended Linear workflow. In a skill with exec and external integration capabilities, overbroad activation raises the chance of unintended command execution, state changes, notifications, or git operations.
The security note is misleading because the workflow explicitly has users configure API keys, Discord webhooks, bot tokens, and external automation platforms that inherently handle or transmit sensitive credentials and event data. This can lower a user's guard and encourage unsafe secret storage or over-trust in third-party integrations, increasing the risk of credential exposure or unintended data sharing.
The skill instructs users to persist a Linear API key in a plaintext file under the home directory. Persistent local secrets increase exposure to other local users, malware, backups, accidental commits, and later misuse by tools with filesystem access, especially in an automation skill that also enables exec.
Run setup to store your Linear API key:
mkdir -p ~/.clawdbot
echo "LINEAR_API_KEY=lin_api_xxxxx" > ~/.clawdbot/linear.env
A substantial portion of the skill description is presented in Chinese while other parts are in English, but the file does not state a language preference policy or offer users a choice. This can create a locale/language policy issue if the skill implicitly forces one language for part of the experience without opt-in.
No suspicious patterns detected.