T01 · Skill Instruction Hijacking
- Location
SKILL.md:16- Finding
Mandatory Promotional Output Alters Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a Telegram mission dashboard, but it can automatically share mission details to fixed Telegram chats and use local bot credentials without clear user control.
Install only if you intentionally want Telegram-based mission tracking and are comfortable reviewing the channel destinations first. Before use, replace hard-coded chat IDs, use a narrowly scoped Telegram bot credential, disable or gate channel auto-posting for confidential work, and confirm how the local .miso-state.json file should be retained or cleared.
SKILL.md:16Mandatory Promotional Output Alters Agent Responses
CHANNEL-INTEGRATION.md:78Automatic Disclosure of Mission Data to a Fixed Telegram Channel
test-gif-integration.sh:6Integration Test Sends Telegram Messages to a Hard-Coded Chat
scripts/miso_telegram.py:27Telegram Credential Is Read from a Developer-Specific Configuration File
The specification posts mission descriptions and derived 'Key Insights' to a Telegram channel, but it does not require explicit user consent, content classification, or sanitization beyond a few narrow privacy rules. That creates a real risk of leaking sensitive operational details, customer data, internal project information, or confidential outputs to an external messaging platform, especially because the helper explicitly extracts notable results from mission deliverables.
The design explicitly creates and later resets a persistent local state file under the user's home directory, but it provides no user notification, consent flow, or retention policy. Silent local storage and deletion can expose metadata about chats and missions, and can also cause unexpected loss of audit/history data when the file is reset automatically.
The skill design performs autonomous message posting, editing, pinning, and unpinning in a chat without describing any user confirmation or opt-in. This can modify shared chat state unexpectedly, creating integrity and trust issues in collaborative spaces and potentially disrupting user workflows or records.
The article explicitly describes automatic posting to a shared channel when missions start or complete, but does not mention consent, audience scope, or safeguards against exposing sensitive work activity. In an agent skill context, this can lead to unintended disclosure of project names, statuses, or other operational metadata to broader audiences than the user expects.
This markdown file contains skill specifications only in Japanese, and there is no indication that users can opt into another language or that the skill is intentionally restricted to a Japanese-only audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
🤖 𝗠𝗜𝗦𝗦𝗜𝗢𝗡 𝗖𝗢𝗡𝗧𝗥𝗢𝗟
↳ 🧩 𝗘𝗫𝗔𝗠𝗣𝗟𝗘 𝟭 𝗖𝗢𝗗𝗘 𝗥𝗘𝗩𝗜𝗪 𝗠𝗜𝗦𝗦𝗜𝗢𝗡
📋 3 agents (linter, reviewer, security-checker)
📋 Phases: INIT → RUNNING → COMPLETE (no approval gate)
——————————————
⏳ INIT
▓░░░░░░░░░░░░░░░░ 0%
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def _api_call(method: str, chat_id: int, message_id: int) -> dict:
token = _get_token()
url = f"https://api.telegram.org/bot{token}/{method}"
payload = json.dumps({"chat_id": chat_id, "message_id": message_id,
"disable_notification": True}).encode("utf-8")
req = Request(url, data=payload, headers={"Content-Type": "application/json"})
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def _api_call(method: str, chat_id: int, message_id: int) -> dict:
token = _get_token()
url = f"https://api.telegram.org/bot{token}/{method}"
payload = json.dumps({"chat_id": chat_id, "message_id": message_id,
"disable_notification": True}).encode("utf-8")
req = Request(url, data=payload, headers={"Content-Type": "application/json"})
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def _api_call(method: str, chat_id: int, message_id: int) -> dict:
token = _get_token()
url = f"https://api.telegram.org/bot{token}/{method}"
payload = json.dumps({"chat_id": chat_id, "message_id": message_id,
"disable_notification": True}).encode("utf-8")
req = Request(url, data=payload, headers={"Content-Type": "application/json"})
The script hard-codes a Telegram chat ID and immediately sends test content to that external destination, creating an outbound data flow without confirmation, configuration validation, or a clear warning to the operator. In an agent/skill context, this is risky because test scripts are often run as-is, and the pattern can leak operational details, prompts, or future substituted data to an unintended third party chat.
The entire markdown file is written in Japanese, including the title, task descriptions, and implementation notes, with no indication that this language choice is optional or required for a Japan-specific workflow. Under the policy for natural-language violations, this can be considered a locale/language constraint imposed without user opt-in or documented justification.
The document defines fixed notification templates and a mandatory posting flow to a team channel, but it does not offer any user option regarding message language or locale formatting. Because SQP-3 covers natural-language policy violations and the templates are fixed natural-language outputs, this can conflict with policies requiring user choice unless the locale is clearly justified.
The document prescribes a Telegram-specific communication format throughout, including statements like 'Left-aligned only', fixed symbols, and Telegram-only rendering rules, but does not indicate any user opt-in or alternative when a different platform or presentation preference may apply. Under the policy, forcing a specific communication mode without choice can be a natural-language policy concern.
Both template examples show timestamps formatted with a fixed JST suffix, which implies a forced locale/timezone choice. The file does not state that this is user-selectable or that the skill is intentionally restricted to a Japan-specific context.
The document includes the untranslated Japanese phrase "味噌 (miso)" in an otherwise English skill description. This introduces a language-specific element without an explicit opt-in, translation policy, or clear region-specific justification in the skill instructions.
The test message includes Japanese-language content directly in the script, and there is no indication that the user can select a language or that the script is intentionally limited to a Japanese locale. This can violate language/locale policy when a specific language is imposed without opt-in or justification.
The edited message payload again contains Japanese text embedded in the script, with no visible option for language selection and no explanation of a locale-specific scope. Repeating the fixed-language behavior in multiple outbound messages reinforces the policy concern.
No suspicious patterns detected.