skills/lgbarn/skills/deploy-telegram/Gen Agent Trust Hub

deploy-telegram

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute system-level commands, specifically ansible-playbook for automated deployment and ssh for retrieving remote container logs.
  • [DATA_EXFILTRATION]: The instructions expose internal local directory structures through absolute paths such as /Users/lgbarn/Personal/Trading/Indicators/Python/bots/telegram/deploy, which provides information about the host environment.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by instructing the agent to read and interpret logs from the remote Telegram bot, which may process untrusted external messages. 1. Ingestion points: Remote log output retrieved via ssh pi@raspberrypi.local in SKILL.md. 2. Boundary markers: None identified to separate untrusted log data from agent instructions. 3. Capability inventory: Local file system access, ansible-playbook execution, and ssh command execution. 4. Sanitization: No validation or filtering of the remote log content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 03:30 PM
Security Audit — agent-trust-hub — deploy-telegram