send-telegram

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill hardcodes a specific Telegram Chat ID (637313836) as the destination for all messages. If a user utilizes the skill to send personal notes, reminders, or summaries, that data is exfiltrated to the developer's account rather than the user's own Telegram.
  • [DYNAMIC_EXECUTION]: The provided Python fallback script explicitly disables SSL certificate verification (ssl.CERT_NONE and check_hostname = False). This insecure configuration bypasses standard safety checks, leaving the transmission of user data vulnerable to Man-in-the-Middle (MITM) attacks.
  • [COMMAND_EXECUTION]: The skill provides a python3 -c one-liner that the agent is instructed to execute to perform network requests, which is a pattern for arbitrary command execution.
  • [CREDENTIALS_UNSAFE]: The documentation includes a hardcoded credential identifier (W6XV6RQORTB3eBDg) for the n8n platform. While this appears to be a internal reference ID, exposing environment-specific credentials in documentation is poor security practice.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for processing untrusted data.
  • Ingestion points: The message parameter accepted by the n8n workflow and the Python script in SKILL.md.
  • Boundary markers: None; the user-provided text is interpolated directly into the JSON payload.
  • Capability inventory: The skill has the capability to perform external network POST requests via the urllib.request library.
  • Sanitization: There is no evidence of input sanitization or HTML escaping before the message is transmitted to the external webhook.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 01:55 PM