Back to skill

Security audit

telegram-alert

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real alerting/notification guide, but it asks for broad execution, file, credential, external messaging, scheduled, and archival capabilities without enough scoping or implementation evidence.

Review this skill before installing. Only use it in an isolated environment, pin and audit dependencies yourself, keep bot/webhook/email credentials out of shared files and source control, and require explicit user approval before any broadcast, scheduled send, custom script, or command execution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:196
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:196-200
Vulnerability Type: Supply-chain exposure through mutable dependencies
Risk Level: Medium

Vulnerable Snippet

markdown
| python-telegram-bot | Python library | Required | `pip install python-telegram-bot` |
| requests | Python library | Required | `pip install requests` |
| matplotlib | Python library | Optional | `pip install matplotlib` |
| Jinja2 | Python library | Optional | `pip install jinja2` |
| psycopg2 | Python library | Optional | `pip install psycopg2-binary` |

The installation instructions at line 134 also direct execution of:

bash
pip install -r requirements_pro.txt

However, requirements_pro.txt is not present in the audited project.

Technical Analysis

The documented installation commands do not constrain dependency versions or verify package integrity with cryptographic hashes. Package resolution can therefore produce different code depending on when installation occurs and which package index is used.

This does not establish that any currently named package is malicious. It creates a supply-chain exposure in which a compromised upstream release, unsafe package-index configuration, dependency confusion, or future malicious release could be installed without additional verification.

The missing requirements_pro.txt also prevents auditors from verifying the primary dependency set that the Skill instructs users to install.

Attack Path

  1. A user or AI agent follows the Skill's setup instructions.
  2. The installation command resolves packages from the configured Python package index.
  3. An unpinned direct or transitive dependency resolves to a compromised or otherwise unsafe release.
  4. Package installation hooks or imported runtime code execute with the privileges of the user running pip or the Skill.
  5. The compromised package can access resources available to that account, potentially in ...[truncated 572 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add the referenced requirements_pro.txt to the project so its contents can be reviewed.
  2. Pin every direct dependency to an audited version.
  3. Generate and verify cryptographic hashes, such as by using pip install --require-hashes.
  4. Use a reviewed lock file and include transitive dependencies in dependency scanning.
  5. Restrict installation to an explicitly configured trusted package index.
  6. Install dependencies in an isolated virtual environment under a non-privileged account.
  7. Add automated vulnerability and provenance checks to the release process.
  8. Regularly update pinned versions through a controlled review and testing workflow.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:202
Finding

Guidance Permits Plaintext Credential Storage in Local Configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:202-209
Vulnerability Type: Insecure storage of sensitive credentials
Risk Level: Medium

Vulnerable Snippet

The following is an English rendering of the relevant documentation statement:

markdown
- All credentials are stored in local configuration files.

The initialization instructions at lines 136-138 additionally direct users to create a local configuration file and populate channel credentials:

bash
cp config_pro_template.yaml config_pro.yaml
# Populate the credentials for each channel.

Technical Analysis

The Skill documents environment-variable names but also explicitly states that credentials are stored in local configuration files. It does not require encryption, restrictive file permissions, an operating-system secret manager, exclusion from backups, or repository safeguards.

Telegram bot tokens, DingTalk and WeCom webhook URLs, webhook secrets, and SMTP credentials are authentication secrets. Storing their raw values in a regular YAML file can expose them to other users, processes, source-control commits, workspace synchronization, backups, or diagnostic archives.

The package contains no implementation capable of enforcing the separate claims that secrets are masked in logs or loaded securely. Because SKILL.md is the only project file, those protections cannot be verified.

Attack Path

  1. A user follows the initialization instructions and creates config_pro.yaml.
  2. The user places channel tokens, webhook URLs, or email credentials directly in that file.
  3. The file is committed to source control, included in a backup, synchronized to a shared workspace, or read by another local process or user.
  4. An unauthorized party obtains the credentials.
  5. The party uses the exposed credentials against the associated notification or email service.

Impact Assessment

Depending on the exposed credential, an at ...[truncated 465 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove instructions that recommend placing raw credentials in YAML configuration files.
  2. Require secret values to be supplied through environment variables, an operating-system credential store, or a managed secret service.
  3. Keep only variable references, such as ${TELEGRAM_BOT_TOKEN}, in configuration files.
  4. Provide a .gitignore entry for local configuration and secret files.
  5. If local secret files must be supported, require restrictive permissions such as mode 0600 on Unix-like systems and an equivalent access-control list on Windows.
  6. Prevent secrets from appearing in logs, exceptions, command histories, exported reports, and delivery-status responses.
  7. Add startup checks that reject configuration files containing raw secrets where practical.
  8. Document credential rotation and immediate revocation procedures for accidentally disclosed tokens.
  9. Apply least privilege to every bot, webhook, and email credential.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Enabling custom script execution for trigger generation or scheduled content materially expands the skill from a notification tool into an arbitrary code-execution surface. In an agent environment with exec/write capabilities, this can be abused to run unintended commands, access local data, or pivot into broader system compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill supports multi-group broadcast, external push notifications, and history archiving, but does not prominently warn that user-provided content may be sent to third parties or stored persistently. That omission is risky because this is a communication skill, so the context makes accidental data exfiltration more likely and more harmful.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger description is overly broad, saying the skill should be used whenever a user needs 'telegram-alert related functionality.' In an agent ecosystem this can cause over-invocation for loosely related requests, increasing the chance of unintended external messaging, credential use, or execution of associated tools.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document claims there are no untrusted external calls, but elsewhere it explicitly describes real-time market data retrieval and outbound calls to Telegram, DingTalk, WeCom, and email APIs. This mismatch can cause users or agents to underestimate data exfiltration and third-party communication risk, leading to unsafe deployment decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The security guidance asserts that only whitelist commands are executed, yet the rest of the document advertises broad command execution without defining the whitelist or enforcement mechanism. This creates a misleading safety claim and may result in unsafe execution paths being trusted by users or agent orchestrators.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest presents the skill as a communication/alerting tool, but later sections broaden it into generic file processing and command execution. This scope creep increases the chance that an agent invokes powerful capabilities outside the user's expectations, which can lead to unauthorized local actions or unsafe tool use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

L264 将调度时区写为“Asia/Shanghai”,而文档其余部分未说明这是默认值、可由用户修改,或该技能仅面向特定地区使用。对跨地区用户而言,这构成了未获用户选择的语言/区域策略约束。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.