telegram-bot-conflict-resolution

Warn

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructs the agent to access sensitive .env files to extract and swap Telegram bot tokens.
  • [COMMAND_EXECUTION]: The procedure involves system-level operations including managing services via launchctl and systemctl, and modifying file paths using sed.
  • [COMMAND_EXECUTION]: Instructions specify creating and configuring persistence mechanisms such as systemd service units and cron jobs on the host machine.
  • [PROMPT_INJECTION]: The skill processes external structured data (XML) and converts it to Markdown while having access to system management tools, which presents a surface for indirect prompt injection. Ingestion points: system.xml. Boundary markers: None. Capability inventory: systemctl, launchctl, systemd, crontab, .env access, sed, rsync. Sanitization: None.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 17, 2026, 07:19 AM
Security Audit — agent-trust-hub — telegram-bot-conflict-resolution