Back to skill

Security audit

miso

Security checks for vulnerabilities and agentic risk

Overview

This is a Telegram mission dashboard, but it can automatically share mission details to fixed Telegram chats and use local bot credentials without clear user control.

Install only if you intentionally want Telegram-based mission tracking and are comfortable reviewing the channel destinations first. Before use, replace hard-coded chat IDs, use a narrowly scoped Telegram bot credential, disable or gate channel auto-posting for confidential work, and confirm how the local .miso-state.json file should be retained or cleared.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:16
Finding

Mandatory Promotional Output Alters Agent Responses

Content
View full analysis
Remediation
View remediation

other

Error
Location
CHANNEL-INTEGRATION.md:78
Finding

Automatic Disclosure of Mission Data to a Fixed Telegram Channel

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
test-gif-integration.sh:6
Finding

Integration Test Sends Telegram Messages to a Hard-Coded Chat

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/miso_telegram.py:27
Finding

Telegram Credential Is Read from a Developer-Specific Configuration File

Content
View full analysis
str: with open(CONFIG_PATH) as f: return json.load(f)["channels"]["telegram"]["botToken"] def _api_call(method: str, chat_id: int, message_id: int) -> dict: token = _get_token() url = f"https://api.telegram.org/bot{token}/{method}" ``` ### Technical Analysis The helper directly opens a sensitive OpenClaw configuration file at an absolute path tied to a specific developer account. It reads the Telegram bot token from a broader application configuration rather than receiving a narrowly scoped credential through a configurable secret interface. A Telegram API credential is legitimately necessary for the declared Telegram helper functions. The observed requests are made to the official `https://api.telegram.org` endpoint, and no evidence shows that the token is sent to another domain. Nevertheless, the implementation violates portability and least-privilege design principles by coupling the helper to a complete user configuration file. The bot token is also embedded in the request URL, as required by Telegram's Bot API format. If exceptions, proxies, or future debug logging record complete URLs, the token could be exposed in logs. ### Attack Path 1. A caller runs a pin, unpin, send, or edit operation. 2. `_get_token()` opens `/Users/shunsukehayashi/.openclaw/openclaw.json`. 3. The function extracts `channels.telegram.botToken`. 4. The token is interpolated into a Telegram Bot API URL. 5. The helper performs the requested network operation. 6. If full request URLs are logged by surrounding infrastructure, the credential may ...[truncated 491 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (17)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The specification posts mission descriptions and derived 'Key Insights' to a Telegram channel, but it does not require explicit user consent, content classification, or sanitization beyond a few narrow privacy rules. That creates a real risk of leaking sensitive operational details, customer data, internal project information, or confidential outputs to an external messaging platform, especially because the helper explicitly extracts notable results from mission deliverables.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The design explicitly creates and later resets a persistent local state file under the user's home directory, but it provides no user notification, consent flow, or retention policy. Silent local storage and deletion can expose metadata about chats and missions, and can also cause unexpected loss of audit/history data when the file is reset automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill design performs autonomous message posting, editing, pinning, and unpinning in a chat without describing any user confirmation or opt-in. This can modify shared chat state unexpectedly, creating integrity and trust issues in collaborative spaces and potentially disrupting user workflows or records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The article explicitly describes automatic posting to a shared channel when missions start or complete, but does not mention consent, audience scope, or safeguards against exposing sensitive work activity. In an agent skill context, this can lead to unintended disclosure of project names, statuses, or other operational metadata to broader audiences than the user expects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains skill specifications only in Japanese, and there is no indication that users can opt into another language or that the skill is intentionally restricted to a Japanese-only audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · examples/EXAMPLES.md (reported line 4)May include surrounding context.

md
🤖 𝗠𝗜𝗦𝗦𝗜𝗢𝗡 𝗖𝗢𝗡𝗧𝗥𝗢𝗟
↳ 🧩 𝗘𝗫𝗔𝗠𝗣𝗟𝗘 𝟭 𝗖𝗢𝗗𝗘 𝗥𝗘𝗩𝗜𝗪 𝗠𝗜𝗦𝗦𝗜𝗢𝗡
📋 3 agents (linter, reviewer, security-checker)
📋 Phases: INIT → RUNNING → COMPLETE (no approval gate)
——————————————
⏳ INIT
▓░░░░░░░░░░░░░░░░ 0%

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/miso_telegram.py (reported line 34)May include surrounding context.

python
def _api_call(method: str, chat_id: int, message_id: int) -> dict:
    token = _get_token()
    url = f"https://api.telegram.org/bot{token}/{method}"
    payload = json.dumps({"chat_id": chat_id, "message_id": message_id,
                          "disable_notification": True}).encode("utf-8")
    req = Request(url, data=payload, headers={"Content-Type": "application/json"})

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/miso_telegram.py (reported line 93)May include surrounding context.

python
def _api_call(method: str, chat_id: int, message_id: int) -> dict:
    token = _get_token()
    url = f"https://api.telegram.org/bot{token}/{method}"
    payload = json.dumps({"chat_id": chat_id, "message_id": message_id,
                          "disable_notification": True}).encode("utf-8")
    req = Request(url, data=payload, headers={"Content-Type": "application/json"})

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/miso_telegram.py (reported line 116)May include surrounding context.

python
def _api_call(method: str, chat_id: int, message_id: int) -> dict:
    token = _get_token()
    url = f"https://api.telegram.org/bot{token}/{method}"
    payload = json.dumps({"chat_id": chat_id, "message_id": message_id,
                          "disable_notification": True}).encode("utf-8")
    req = Request(url, data=payload, headers={"Content-Type": "application/json"})

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script hard-codes a Telegram chat ID and immediately sends test content to that external destination, creating an outbound data flow without confirmation, configuration validation, or a clear warning to the operator. In an agent/skill context, this is risky because test scripts are often run as-is, and the pattern can leak operational details, prompts, or future substituted data to an unintended third party chat.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire markdown file is written in Japanese, including the title, task descriptions, and implementation notes, with no indication that this language choice is optional or required for a Japan-specific workflow. Under the policy for natural-language violations, this can be considered a locale/language constraint imposed without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The document defines fixed notification templates and a mandatory posting flow to a team channel, but it does not offer any user option regarding message language or locale formatting. Because SQP-3 covers natural-language policy violations and the templates are fixed natural-language outputs, this can conflict with policies requiring user choice unless the locale is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The document prescribes a Telegram-specific communication format throughout, including statements like 'Left-aligned only', fixed symbols, and Telegram-only rendering rules, but does not indicate any user opt-in or alternative when a different platform or presentation preference may apply. Under the policy, forcing a specific communication mode without choice can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Both template examples show timestamps formatted with a fixed JST suffix, which implies a forced locale/timezone choice. The file does not state that this is user-selectable or that the skill is intentionally restricted to a Japan-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The document includes the untranslated Japanese phrase "味噌 (miso)" in an otherwise English skill description. This introduces a language-specific element without an explicit opt-in, translation policy, or clear region-specific justification in the skill instructions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The test message includes Japanese-language content directly in the script, and there is no indication that the user can select a language or that the script is intentionally limited to a Japanese locale. This can violate language/locale policy when a specific language is imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The edited message payload again contains Japanese text embedded in the script, with no visible option for language selection and no explanation of a locale-specific scope. Repeating the fixed-language behavior in multiple outbound messages reinforces the policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.