telegram
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The
bashtool defined inagents/openai.yamlis vulnerable to command injection. Thefull_base_commandinterpolates the${JSON_PAYLOAD}variable directly into a shell command string using single quotes. If the payload contains a single quote and a semicolon, an attacker can execute arbitrary shell commands on the host system. This is a critical risk given the skill's purpose of processing external event data. - [DYNAMIC_EXECUTION]: The
hookmode (references/hook.md) requires the agent to dynamically generate and write executable bash scripts to the filesystem. This process uses templates and extracted fields from hook payloads, creating a risk of executing injected malicious code if the payload contents are not perfectly sanitized before being written into executable files. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Kafka event streams and Claude Code hook payloads as documented in
references/route.mdandreferences/hook.md. While the skill suggests scrubbing sensitive fields, it lacks explicit boundary markers or instructions to treat this external content as untrusted data. Given the skill's capabilities (shell access viabashand filesystem access viawrite_file), this creates a significant attack surface where malicious data could influence agent actions. - [CREDENTIALS_UNSAFE]: The skill manages the
TELEGRAM_BOT_TOKENcredential. Although the instructions mandate secure file permissions (chmod 600) and forbid printing the token in logs, storing the token in a local configuration file provides a persistent credential that could be targeted for exfiltration if the environment is compromised through other vectors.
Recommendations
- AI detected serious security threats
Audit Metadata