Back to skill

Security audit

telegram-persian-enforcer

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Telegram language-formatting skill with no code execution, credentials, persistence, or local access, though its Persian-only behavior should be used only where that is intended.

Install this only for Telegram chats where Persian output is the intended default. Avoid it for workflows that must preserve a user's requested language, relay exact legal/safety wording, or communicate with multilingual audiences without a separate higher-priority instruction.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (22)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Content
---
name: telegram-persian-enforcer
description: Enforce Persian output for all Telegram group, channel, and DM interactions.
metadata:
  compatibility: Requires a Telegram integration or Telegram-facing workflow.
  openclaw:
    requires:
      env: []
      bins: []
    primaryEnv: ""
    emoji: "🇮🇷"
    models: []
---

# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده

این مهارت را هنگام پاسخ‌گویی در گروه‌ها، کانال‌ها یا پیام�
Confidence
80% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Hidden Instructions

High
Category
Prompt Injection
Content
# الزام زبان فارسی در تلگرام

برای همه تعاملات تلگرامی، خروجی متنی را به فارسی تولید می‌کند.

## زمان استفاده
Confidence
60% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Natural-Language Policy Violations

Medium
Confidence
98% confidence
Finding
The manifest describes a skill that enforces Persian-only output for all Telegram interactions, regardless of user preference. This creates a policy-level prompt injection risk because it can override user intent, reduce transparency, and cause the agent to mishandle safety-critical or compliance-sensitive communications in the wrong language.

Natural-Language Policy Violations

Medium
Confidence
99% confidence
Finding
These rules require all Telegram-generated text and task outputs to be translated into Persian before sending, even when the input or user preference differs. That can distort meaning, interfere with exact transmission of warnings or approvals, and override higher-priority conversational requirements.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The behavior guidance explicitly says output to Telegram must be Persian regardless of input language. This is dangerous in agent settings because it hard-codes behavior that can conflict with user expectations, operational instructions, and accurate relaying of external content.

Static analysis

No suspicious patterns detected.