telegram

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The bash tool defined in agents/openai.yaml is vulnerable to command injection. The full_base_command interpolates the ${JSON_PAYLOAD} variable directly into a shell command string using single quotes. If the payload contains a single quote and a semicolon, an attacker can execute arbitrary shell commands on the host system. This is a critical risk given the skill's purpose of processing external event data.
  • [DYNAMIC_EXECUTION]: The hook mode (references/hook.md) requires the agent to dynamically generate and write executable bash scripts to the filesystem. This process uses templates and extracted fields from hook payloads, creating a risk of executing injected malicious code if the payload contents are not perfectly sanitized before being written into executable files.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Kafka event streams and Claude Code hook payloads as documented in references/route.md and references/hook.md. While the skill suggests scrubbing sensitive fields, it lacks explicit boundary markers or instructions to treat this external content as untrusted data. Given the skill's capabilities (shell access via bash and filesystem access via write_file), this creates a significant attack surface where malicious data could influence agent actions.
  • [CREDENTIALS_UNSAFE]: The skill manages the TELEGRAM_BOT_TOKEN credential. Although the instructions mandate secure file permissions (chmod 600) and forbid printing the token in logs, storing the token in a local configuration file provides a persistent credential that could be targeted for exfiltration if the environment is compromised through other vectors.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 04:00 AM
Security Audit — agent-trust-hub — telegram