Back to skill

Security audit

SZZG007 TalkTrack Telegram

Security checks for vulnerabilities and agentic risk

Overview

This skill is aligned with Telegram sales support, but it asks to remember and learn from customer chats without clear consent, retention, or control details.

Review this skill before installing if your Telegram conversations include personal, customer, pricing, or business-sensitive data. Configure it so conversation memory, auto-learning, Feishu sync, and learned talktrack updates require explicit user approval and have clear retention/deletion rules.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly describes remembering customer history and analyzing Telegram conversations, but it does not warn users that personal/customer conversation data may be stored and processed. In a sales-chat context, this can lead to undisclosed collection of personal or business-sensitive information, creating privacy, consent, and compliance risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states it will automatically learn from successful and failed conversations to optimize the talk-track library, but it does not clearly disclose that prior conversations may be reused for model updates or content generation. This creates a risk that sensitive customer messages, pricing details, objections, or other proprietary information will be repurposed without notice or consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The markdown says the skill will automatically switch between Chinese and English, but it does not indicate that the user can choose or opt in to the language/locale behavior. Under the policy, forcing a language behavior without explicit choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.