Back to skill

Security audit

polymarket-telegram-picks

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent with its stated purpose, but users should understand it sends generated betting-related analysis to Telegram using their bot credentials.

Install only if you want an agent to fetch Polymarket data and send recommendations to a Telegram chat. Prefer environment variables or a managed secret store for TELEGRAM_BOT_TOKEN and TELEGRAM_CHAT_ID, do not commit config/config.json, and review messages before sending if they could include private context. Treat any betting recommendation as speculative and financially risky.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
scripts/send_telegram.py:18
Finding

Telegram bot credentials may be stored in an unprotected plaintext configuration file

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (22)

Tainted flow: 'req' from os.environ.get (line 44, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/send_telegram.py (reported line 45)May include surrounding context.

python
from urllib.parse import urlencode
        body = urlencode({"chat_id": chat_id, "text": text, "disable_web_page_preview": "true"}).encode()
        req = Request(url, data=body, method="POST", headers={"Content-Type": "application/x-www-form-urlencoded"})
        with urlopen(req, timeout=15) as r:
            resp = json.loads(r.read().decode())
            return resp.get("ok") is True
    except Exception as e:

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This mismatch includes an undeclared dependency on Telegram credentials and external transmission behavior, which is security-relevant because users may invoke the skill without understanding that secrets are required and messages are sent to a third-party service. Hidden or underdocumented secret usage and outbound communication reduce informed consent and can lead to accidental data disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This mismatch includes an undeclared dependency on Telegram credentials and external transmission behavior, which is security-relevant because users may invoke the skill without understanding that secrets are required and messages are sent to a third-party service. Hidden or underdocumented secret usage and outbound communication reduce informed consent and can lead to accidental data disclosure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch includes an undeclared dependency on Telegram credentials and external transmission behavior, which is security-relevant because users may invoke the skill without understanding that secrets are required and messages are sent to a third-party service. Hidden or underdocumented secret usage and outbound communication reduce informed consent and can lead to accidental data disclosure.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/run_daily.py (reported line 5)May include surrounding context.

python
#!/usr/bin/env python3
# -*- coding: utf-8 -*-
"""
每日一键执行:拉取 Polymarket 赔率 → 可选 AI 分析 → 推送到 Telegram。
适用于系统 crontab 或单独执行,不经过 OpenClaw 会话。
若需「AI 分析」,请使用 OpenClaw 定时任务触发技能,由助手执行 fetch → 分析 → send_telegram。
"""
import os
import subprocess
import sys
from pathlib import Path

SKILL_ROOT = Path(__file__).resolve().parent.parent
FETCH_SCRIPT = SKILL_ROOT / "scripts" / "fetch_polymarket.py"
SEND_SCRIPT = SKILL_ROOT / "scripts" / "send_telegram.py"


def main():
    if not FETCH_SCRIPT.is_file():
        print(f"未找到脚本: {FETCH_SCRIPT}", file=sys.stderr)
        sys.exit(1)
    result = subprocess.run(
        [sys.ex

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file states that the skill will push AI-generated recommendations to Telegram, which is a third-party network service, but does not include a privacy or data-transmission warning. Under the markdown-specific SQP-2 criteria, descriptions should warn users when behavior may affect privacy or send data off-system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The setup instructions tell users to obtain and place a Telegram bot token and chat ID into environment variables or a config file, but do not warn that the bot token is a secret that grants control over the bot. In the OpenClaw context, encouraging placement of live secrets into local config without explicit protection guidance increases the chance of accidental leakage via version control, logs, screenshots, or shared workspace files.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to use shell, network, file access, and environment-derived secrets, but the manifest does not declare any explicit tool scope or permission boundaries. This creates a least-privilege failure: an agent or platform may grant broader capabilities than users expect, increasing the risk of unintended command execution, data access, or secret use during invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough that unrelated user requests could accidentally invoke a skill that executes scripts and transmits output to Telegram. In this context, unintended invocation is more dangerous because the skill has shell, network, and secret-dependent behavior, so a simple ambiguous phrase may cause external side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs the agent to send generated analysis to Telegram without clearly warning the user that content leaves the local environment and is transmitted to an external service. This is dangerous because the analysis text could contain sensitive context, internal notes, or user-provided data that is then disclosed to a third party without explicit informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction “用简洁中文写出推荐列表与理由” forces a specific language for output. There is no opt-in, user choice, or documented region-specific justification for requiring Chinese, which conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The docstring states the script fetches same-day events using a China-time interpretation, and the implementation consistently applies UTC+8 as the date boundary. This is a natural-language locale choice imposed by default, with no user choice or clear region-specific justification presented to the user.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The generated output labels results using a UTC+8 date context and describes today's games according to that locale, but does not offer the user an alternative timezone or opt-in. This can violate language/locale policy when a specific locale is enforced implicitly for all users.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/run_daily.py (reported line 22)May include surrounding context.

python
if not FETCH_SCRIPT.is_file():
        print(f"未找到脚本: {FETCH_SCRIPT}", file=sys.stderr)
        sys.exit(1)
    result = subprocess.run(
        [sys.executable, str(FETCH_SCRIPT)],
        capture_output=True,
        text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/run_daily.py (reported line 43)May include surrounding context.

python
if not SEND_SCRIPT.is_file():
        print("未找到 send_telegram.py,仅输出摘要:\n", summary)
        return
    send = subprocess.run(
        [sys.executable, str(SEND_SCRIPT), message],
        cwd=str(SKILL_ROOT),
        timeout=15,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language descriptions and runtime messages that force a specific language/locale for all users. The policy for SQP-3 flags language or locale constraints when the skill does not offer user choice or clearly justify the restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script posts arbitrary text to the Telegram Bot API, which can transmit user or system data off-host. Although the file has a brief docstring saying it sends messages to Telegram, there is no runtime disclosure or confirmation before sending potentially sensitive stdin or command-line content to an external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

md
def send_message(text: str, token: str, chat_id: str) -> bool:
    """通过 Telegram Bot API 发送文本。"""
    url = f"https://api.telegram.org/bot{token}/sendMessage"
    try:
        from urllib.request import urlopen, Request
        from urllib.parse import urlencode

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/send_telegram.py (reported line 39)May include surrounding context.

python
def send_message(text: str, token: str, chat_id: str) -> bool:
    """通过 Telegram Bot API 发送文本。"""
    url = f"https://api.telegram.org/bot{token}/sendMessage"
    try:
        from urllib.request import urlopen, Request
        from urllib.parse import urlencode

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example values for both configuration fields are written only in Chinese, which imposes a specific language on users without any opt-in or alternative locale. This matches the language/locale policy concern for natural-language content in config files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code performs HTTP requests to the Polymarket Gamma API, but aside from the module docstring there is no runtime user-facing notice that the script contacts an external service. For code files, network calls can warrant disclosure when there is no visible prompt or logging, and the operation happens automatically on execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring is written entirely in Chinese and describes the skill's behavior only in that language. This can constitute a language/locale policy violation because the skill appears to assume a specific language without offering user choice or documenting an opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.