telegram-crabbox-e2e-proof

Warn

Audited by Snyk on May 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill explicitly opens and reads real Telegram user chats as part of its workflow (e.g., using the crabbox commands and python3 /tmp/openclaw-telegram-user-crabbox/user-driver.py transcript and deep-linking to message IDs in SKILL.md), so the agent ingests untrusted, user-generated third-party messages that could contain instructions affecting subsequent actions.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The skill passes http://artifacts.openclaw.ai/tdlib-v1.8.0-linux-x64.tgz to the runner at runtime via --tdlib-url to fetch and restore TDLib/Telegram Desktop (a required native bundle that will be extracted/executed), so this external tarball is a runtime-fetched executable dependency that can run remote code.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 10, 2026, 05:57 PM
Issues
2
Security Audit — snyk — telegram-crabbox-e2e-proof