T01 · Skill Instruction Hijacking
- Location
SKILL.md:218- Finding
Hard-Coded Third-Party Telegram Recipient Enables Unauthorized Error-Data Disclosure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a workflow-migration template, but it bakes in person-specific Kevin assumptions and a fixed Telegram chat ID that could send workflow failure details to an unintended recipient.
Review carefully before installing. Remove Kevin-specific instructions, remove the fixed TELEGRAM_CHAT_ID, make external alerts explicitly opt-in to a user-owned destination, and redact or avoid payload logging before using this to migrate workflows that handle business data, customer data, or secrets.
SKILL.md:218Hard-Coded Third-Party Telegram Recipient Enables Unauthorized Error-Data Disclosure
SKILL.md:132Dry-Run Templates Persist Complete HTTP Request Payloads in Logs
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
log = logging.getLogger(__name__)
# ─── Config ────────────────────────────────────────────────────────────────────
API_KEY = os.getenv("API_KEY") # from .env
WEBHOOK_URL = os.getenv("WEBHOOK_URL") # destination
DRY_RUN = False
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
log = logging.getLogger(__name__)
# ─── Config ────────────────────────────────────────────────────────────────────
API_KEY = os.getenv("API_KEY") # from .env
WEBHOOK_URL = os.getenv("WEBHOOK_URL") # destination
DRY_RUN = False
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
log = logging.getLogger(__name__)
# ─── Config ────────────────────────────────────────────────────────────────────
API_KEY = os.getenv("API_KEY") # from .env
WEBHOOK_URL = os.getenv("WEBHOOK_URL") # destination
DRY_RUN = False
Referenced artifact was not completely inspected
- Generate a `SKILL.md` in the same output directory
Referenced artifact was not completely inspected
- Generate a `SKILL.md` in the same output directory
The skill hard-codes 'Kevin' as the request authority for language choice, embedding a person-specific operational assumption into a reusable automation tool. While not directly exploitable on its own, this can misroute decisions, normalize recipient-specific behavior, and contributes to unsafe user-context confusion in generated outputs.
The skill instructs generated workflows to send failure alerts using a hard-coded Telegram destination tied to a specific person/context ('Kevin's bot token if available'). That introduces an unnecessary outbound communication path and can cause operational data, error details, or sensitive metadata to be exfiltrated to an unintended third party during failures.
The same line that defines failure alerts also bakes in person-specific organizational context ('Kevin's bot token'), which increases the risk that generated workflows inherit hidden routing assumptions for secrets and notifications. In an automation-migration skill, that context is unjustified and can lead to unauthorized disclosure of runtime errors or business data.
Embedding a specific Telegram chat ID in .env.example seeds generated projects with a recipient-controlled messaging channel that is unrelated to core workflow migration. If the generated script later enables alerts, failures or runtime data may be sent to that fixed external recipient without the user's informed consent.
No suspicious patterns detected.