Back to skill

Security audit

Telegram Chat To Image

Security checks for vulnerabilities and agentic risk

Overview

This skill locally converts a user-provided Telegram JSON export into a PNG image, with no evidence of hidden networking, persistence, credential access, or destructive behavior.

Install Pillow in a virtual environment, consider pinning the dependency yourself, and run the tool only on Telegram exports you trust. Be careful with very large exports or extreme --width values, and choose an output path that will not overwrite something important.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:26
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
--hash=sha256: ``` Install it with: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. Use a trusted, explicitly configured package index or an internally controlled artifact repository. 4. Review and update the pinned dependency regularly to incorporate security fixes. 5. Perform installation in an isolated virtual environment with no administrative privileges. 6. Where practical, verify dependency provenance and retain a software bill of materials for release artifacts. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/chat_to_image.py:266
Finding

Unbounded Image Dimensions Allow Resource Exhaustion

Content
View full analysis
Remediation
View remediation
MAX_HEIGHT: raise ValueError("Calculated image height exceeds the permitted limit") if self.width <= 0 or self.width * total_h > MAX_PIXELS: raise ValueError("Image dimensions exceed the permitted pixel limit") ``` 4. Estimate memory consumption before allocation and reject jobs that exceed a configured budget. 5. Split long conversations into multiple bounded images rather than creating one monolithic image. 6. Consider streaming JSON parsing for large exports so the complete document does not have to reside in memory. 7. Catch `MemoryError`, Pillow dimension errors, JSON decoding errors, and output I/O errors to fail cleanly without destabilizing a larger service. 8. If exposed through a service, enforce operating-system or container-level CPU, memory, execution-time, and concurrency limits as defense in depth. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is primarily written in English, but the changelog entries at L13-L18 switch to Chinese with no opt-in, translation, or justification. This can violate language/locale policy expectations because users are forced to interpret part of the skill documentation in a specific language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code performs a file write via img.save(output, "PNG", quality=95). Although the CLI argument names imply output generation, there is no confirmation prompt or explicit user-facing warning near the write operation or in comments/docstrings about creating or overwriting the destination file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.