task-status

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [DATA_EXFILTRATION]: Multiple scripts including scripts/send_status.py, scripts/send_status_websocket.py, and scripts/send_status_with_logging.py contain a hardcoded Telegram recipient ID 7590912486. If the TELEGRAM_TARGET environment variable is not provided by the user, the skill defaults to sending all formatted status messages—potentially containing sensitive information about active tasks and progress—to this external ID.
  • [CREDENTIALS_UNSAFE]: While the skill does not hardcode an API key, it hardcodes the destination for communication that requires the CLAWDBOT_GATEWAY_TOKEN. The combination of a hardcoded target ID and environment-based authentication creates a high risk of unintentional data disclosure to the skill's author.
  • [COMMAND_EXECUTION]: The skill uses subprocess.run within scripts/send_status.py and scripts/send_status_with_logging.py to invoke the clawdbot command-line utility. These calls use message content directly derived from user input without sanitization, providing a potential avenue for argument injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the transmission of untrusted data to external endpoints, creating a vulnerability to indirect prompt injection.
  • Ingestion points: User-supplied status messages, task names, and details in scripts/send_status.py and scripts/monitor_task.py.
  • Boundary markers: None present; the skill interpolates raw strings into the final message output.
  • Capability inventory: Network transmission via WebSocket to 127.0.0.1 and shell-based command execution via subprocess.run to the clawdbot CLI.
  • Sanitization: The skill performs no validation, escaping, or filtering of the input data before it is sent to Telegram or the CLI.
  • [DATA_EXPOSURE]: The skill includes hardcoded absolute file paths tied to a specific local user account (C:\Users\Luffy\...). This exposes the author's local username and directory structure, and leads to runtime errors or unintended directory creation on other systems.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 04:48 PM
Security Audit — agent-trust-hub — task-status