T09 · Insecure Skill Coding Practices
- Location
scripts/send_telegram.py:18- Finding
Telegram bot credentials may be stored in an unprotected plaintext configuration file
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent with its stated purpose, but users should understand it sends generated betting-related analysis to Telegram using their bot credentials.
Install only if you want an agent to fetch Polymarket data and send recommendations to a Telegram chat. Prefer environment variables or a managed secret store for TELEGRAM_BOT_TOKEN and TELEGRAM_CHAT_ID, do not commit config/config.json, and review messages before sending if they could include private context. Treat any betting recommendation as speculative and financially risky.
scripts/send_telegram.py:18Telegram bot credentials may be stored in an unprotected plaintext configuration file
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
from urllib.parse import urlencode
body = urlencode({"chat_id": chat_id, "text": text, "disable_web_page_preview": "true"}).encode()
req = Request(url, data=body, method="POST", headers={"Content-Type": "application/x-www-form-urlencoded"})
with urlopen(req, timeout=15) as r:
resp = json.loads(r.read().decode())
return resp.get("ok") is True
except Exception as e:
This mismatch includes an undeclared dependency on Telegram credentials and external transmission behavior, which is security-relevant because users may invoke the skill without understanding that secrets are required and messages are sent to a third-party service. Hidden or underdocumented secret usage and outbound communication reduce informed consent and can lead to accidental data disclosure.
This mismatch includes an undeclared dependency on Telegram credentials and external transmission behavior, which is security-relevant because users may invoke the skill without understanding that secrets are required and messages are sent to a third-party service. Hidden or underdocumented secret usage and outbound communication reduce informed consent and can lead to accidental data disclosure.
This mismatch includes an undeclared dependency on Telegram credentials and external transmission behavior, which is security-relevant because users may invoke the skill without understanding that secrets are required and messages are sent to a third-party service. Hidden or underdocumented secret usage and outbound communication reduce informed consent and can lead to accidental data disclosure.
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
#!/usr/bin/env python3
# -*- coding: utf-8 -*-
"""
每日一键执行:拉取 Polymarket 赔率 → 可选 AI 分析 → 推送到 Telegram。
适用于系统 crontab 或单独执行,不经过 OpenClaw 会话。
若需「AI 分析」,请使用 OpenClaw 定时任务触发技能,由助手执行 fetch → 分析 → send_telegram。
"""
import os
import subprocess
import sys
from pathlib import Path
SKILL_ROOT = Path(__file__).resolve().parent.parent
FETCH_SCRIPT = SKILL_ROOT / "scripts" / "fetch_polymarket.py"
SEND_SCRIPT = SKILL_ROOT / "scripts" / "send_telegram.py"
def main():
if not FETCH_SCRIPT.is_file():
print(f"未找到脚本: {FETCH_SCRIPT}", file=sys.stderr)
sys.exit(1)
result = subprocess.run(
[sys.ex
This markdown file states that the skill will push AI-generated recommendations to Telegram, which is a third-party network service, but does not include a privacy or data-transmission warning. Under the markdown-specific SQP-2 criteria, descriptions should warn users when behavior may affect privacy or send data off-system.
The setup instructions tell users to obtain and place a Telegram bot token and chat ID into environment variables or a config file, but do not warn that the bot token is a secret that grants control over the bot. In the OpenClaw context, encouraging placement of live secrets into local config without explicit protection guidance increases the chance of accidental leakage via version control, logs, screenshots, or shared workspace files.
The skill instructs the agent to use shell, network, file access, and environment-derived secrets, but the manifest does not declare any explicit tool scope or permission boundaries. This creates a least-privilege failure: an agent or platform may grant broader capabilities than users expect, increasing the risk of unintended command execution, data access, or secret use during invocation.
The trigger phrases are broad enough that unrelated user requests could accidentally invoke a skill that executes scripts and transmits output to Telegram. In this context, unintended invocation is more dangerous because the skill has shell, network, and secret-dependent behavior, so a simple ambiguous phrase may cause external side effects.
The skill directs the agent to send generated analysis to Telegram without clearly warning the user that content leaves the local environment and is transmitted to an external service. This is dangerous because the analysis text could contain sensitive context, internal notes, or user-provided data that is then disclosed to a third party without explicit informed consent.
The instruction “用简洁中文写出推荐列表与理由” forces a specific language for output. There is no opt-in, user choice, or documented region-specific justification for requiring Chinese, which conflicts with the language/locale policy criteria.
The docstring states the script fetches same-day events using a China-time interpretation, and the implementation consistently applies UTC+8 as the date boundary. This is a natural-language locale choice imposed by default, with no user choice or clear region-specific justification presented to the user.
The generated output labels results using a UTC+8 date context and describes today's games according to that locale, but does not offer the user an alternative timezone or opt-in. This can violate language/locale policy when a specific locale is enforced implicitly for all users.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if not FETCH_SCRIPT.is_file():
print(f"未找到脚本: {FETCH_SCRIPT}", file=sys.stderr)
sys.exit(1)
result = subprocess.run(
[sys.executable, str(FETCH_SCRIPT)],
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if not SEND_SCRIPT.is_file():
print("未找到 send_telegram.py,仅输出摘要:\n", summary)
return
send = subprocess.run(
[sys.executable, str(SEND_SCRIPT), message],
cwd=str(SKILL_ROOT),
timeout=15,
This code file contains natural-language descriptions and runtime messages that force a specific language/locale for all users. The policy for SQP-3 flags language or locale constraints when the skill does not offer user choice or clearly justify the restriction.
The script posts arbitrary text to the Telegram Bot API, which can transmit user or system data off-host. Although the file has a brief docstring saying it sends messages to Telegram, there is no runtime disclosure or confirmation before sending potentially sensitive stdin or command-line content to an external service.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def send_message(text: str, token: str, chat_id: str) -> bool:
"""通过 Telegram Bot API 发送文本。"""
url = f"https://api.telegram.org/bot{token}/sendMessage"
try:
from urllib.request import urlopen, Request
from urllib.parse import urlencode
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def send_message(text: str, token: str, chat_id: str) -> bool:
"""通过 Telegram Bot API 发送文本。"""
url = f"https://api.telegram.org/bot{token}/sendMessage"
try:
from urllib.request import urlopen, Request
from urllib.parse import urlencode
The example values for both configuration fields are written only in Chinese, which imposes a specific language on users without any opt-in or alternative locale. This matches the language/locale policy concern for natural-language content in config files.
This code performs HTTP requests to the Polymarket Gamma API, but aside from the module docstring there is no runtime user-facing notice that the script contacts an external service. For code files, network calls can warrant disclosure when there is no visible prompt or logging, and the operation happens automatically on execution.
The module docstring is written entirely in Chinese and describes the skill's behavior only in that language. This can constitute a language/locale policy violation because the skill appears to assume a specific language without offering user choice or documenting an opt-in.
No suspicious patterns detected.