telegram-bot-conflict-resolution
Warn
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructs the agent to access sensitive .env files to extract and swap Telegram bot tokens.
- [COMMAND_EXECUTION]: The procedure involves system-level operations including managing services via launchctl and systemctl, and modifying file paths using sed.
- [COMMAND_EXECUTION]: Instructions specify creating and configuring persistence mechanisms such as systemd service units and cron jobs on the host machine.
- [PROMPT_INJECTION]: The skill processes external structured data (XML) and converts it to Markdown while having access to system management tools, which presents a surface for indirect prompt injection. Ingestion points: system.xml. Boundary markers: None. Capability inventory: systemctl, launchctl, systemd, crontab, .env access, sed, rsync. Sanitization: None.
Audit Metadata