configure-notifications

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill is designed to collect and manage sensitive authentication data, including Telegram Bot tokens, Discord Webhook URLs, Discord Bot tokens, and Slack Webhook URLs. These secrets are stored in a local configuration file at ~/.claude/.omc-config.json.
  • [COMMAND_EXECUTION]: The skill includes a 'Generic CLI Command Flow' that allows users to configure arbitrary shell commands to be executed when specific agent events occur. While it includes instructions to validate that the command contains no shell metacharacters, this feature provides a mechanism for persistent command execution on the host machine.
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to official service APIs (Telegram, Discord, Slack) to validate tokens and send test notifications. It specifically fetches data from api.telegram.org to assist users in finding their Chat ID.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources, creating a potential surface for indirect injection if these sources are compromised.
  • Ingestion points: Processes output from curl requests to the Telegram API and legacy configuration files (omc_config.openclaw.json).
  • Boundary markers: No explicit delimiters are used when processing the data returned from external API calls.
  • Capability inventory: The skill possesses file-write capabilities (.omc-config.json), network request capabilities (curl), and shell command execution.
  • Sanitization: Relies on jq for parsing structured data and includes natural language validation steps for user-provided tokens.
  • [DYNAMIC_EXECUTION]: The skill enables the generation and storage of command templates (using variables like {{sessionId}}) that are dynamically assembled and executed at a later time by the notification system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:34 PM
Security Audit — agent-trust-hub — configure-notifications