T09 · Insecure Skill Coding Practices
- Location
scripts/generate_daily.py:47- Finding
Telegram Bot Token May Be Disclosed Through Persistent Exception Logs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it says, but it handles messaging credentials and unattended pushes with enough under-disclosed and weakly scoped behavior that users should review it carefully before installing.
Install only if you are comfortable with a Chinese-language daily automation that writes Markdown files locally and may send generated content to Telegram on a schedule. Use --no-send or --dry-run first, set a dedicated Telegram bot/chat, restrict the output directory, avoid running install.sh with elevated privileges, and rotate the bot token if logs may already contain failed Telegram request details.
scripts/generate_daily.py:47Telegram Bot Token May Be Disclosed Through Persistent Exception Logs
scripts/install.sh:17Mutable Dependency Range Is Installed Globally Without Integrity Verification
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
try:
logger.info("调用 DeepSeek API 生成硬核深度解读(v5.0 协议)...")
resp = httpx.post(
f"{DEEPSEEK_BASE_URL}/chat/completions",
headers={
"Authorization": f"Bearer {DEEPSEEK_API_KEY}",
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
e,
save_files,
setup_logging
)
from deep_gen import (
generate_deep_analysis,
create_deep_document,
format_deep_telegram_message
)
except ImportError as e:
logging.error(f"导入模块失败: {e}")
sys.exit(1)
def send_telegram(message: str) -> bool:
"""发送 Telegram 消息"""
try:
import requests
bot_token = os.environ.get('TELEGRAM_BOT_TOKEN')
chat_id = os.environ.get('TELEGRAM_CHAT_ID')
if not bot_token or not chat_id:
logging.warning("未配置 Telegram BOT_TOKEN 或 CHAT_ID")
return False
url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
data = {
'chat_id': chat_id,
'text': message,
'parse_mode': 'HTML',
'disable_web_page_preview': True
}
response = requests.post(url, data=data, timeout=30)
result = response.json()
if result.get('ok'):
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
'disable_web_page_preview': True
}
response = requests.post(url, data=data, timeout=30)
result = response.json()
if result.get('ok'):
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
}).encode()
req = urllib.request.Request(url, data=data, method="POST")
with urllib.request.urlopen(req, timeout=30) as response:
result = json.loads(response.read().decode())
if result.get("ok"):
logger.info("Telegram推送成功")
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
}).encode()
token_req = urllib.request.Request(token_url, data=token_data, method="POST")
with urllib.request.urlopen(token_req, timeout=30) as token_response:
token_result = json.loads(token_response.read().decode())
if not token_result.get("code") == 0:
logger.error(f"飞书认证失败: {token_result.get('msg')}")
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
}
)
with urllib.request.urlopen(msg_req, timeout=30) as msg_response:
msg_result = json.loads(msg_response.read().decode())
if msg_result.get("code") == 0:
logger.info("飞书推送成功")
描述强调的是一个完整的“每日毛选语录硬核推送”能力集合,包括 AI 深度解读、配图、语音,以及通过 Obsidian 和 Telegram 进行多渠道推送。而代码片段的实际职责更窄:它是一个“深度解读生成模块”,负责向 DeepSeek API 发送提示词、获取生成内容、按六章结构解析,并格式化为文档字符串和 Telegram 消息字符串。代码并没有展示图片生成、语音合成、文件写入 Obsidian 仓库、或向 Telegram API 发送消息等关键行为。另一个明显差异是,代码确实具备外部网络调用能力(访问 DeepSeek API),但声明权限为空。虽然部分描述内容(硬核解读、六章结构、拒绝鸡汤、直击本质)与代码高度一致,但整体技能描述覆盖了更多未在此代码中实现的核心功能,因此应判定为描述与代码行为存在实质性不匹配。
该代码块与“每日毛选语录 + AI 深度解读 + Telegram 推送”的核心用途基本一致:会获取当日语录、调用 AI 生成深度内容、生成文档并通过 Telegram 发送消息。但描述中强调的若干能力在此代码中没有体现,尤其是“配图”“语音”以及“Obsidian+Telegram 多渠道推送”。当前代码只实现了文本内容生成、本地文件保存和 Telegram 文本消息发送。从审计标准看,这属于描述包含了该代码块未展示的重要能力,因此应判定为存在描述与行为不一致。
该描述与此代码片段存在明显不一致。代码的核心功能是“读取已生成文档并推送消息”,而不是生成“AI深度解读”内容本身。它只从 Markdown 中抽取若干段落,并截断分析内容后发送。与此同时,代码具备实际的外部网络通信能力:调用 Telegram Bot API 和飞书开放平台发送消息,但声明的 permissions 为空,且描述只明确提到 Telegram/Obsidian,没有清楚声明飞书渠道。描述中强调的六章结构、2000+字硬核解读、阶级分析等内容在此代码里没有实现,因此若将整个技能描述套到这段代码上,会夸大/偏移其主要行为。
从该代码块看,实际功能是基础工具支持,而不是描述中的完整技能能力。它会读取本地 JSON 配置与语录数据,选取一条语录,生成一个明确标注为“AI生成失败时的回退方案/简单模式”的文档和 Telegram 消息模板,并把 Markdown 保存到本地目录。虽然配置中出现 voice_enabled、channels、template_file,且输出目录指向 Obsidian 路径,也有 Telegram 消息格式化函数,但这些都只是占位或辅助,当前代码并未执行语音生成、图片生成、消息发送或 AI 深度解读。故描述明显高于代码实际行为,属于描述与实现不一致。
The README presents the skill entirely in Chinese and describes fixed Chinese-language content generation and delivery, but does not indicate that language is configurable or optional. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.
The README explicitly advertises automatic generation and delivery of content to local storage and Telegram, but it does not clearly warn that the skill will write files and transmit generated content to external services once configured. In an agent/automation context, missing disclosure can cause users to enable unattended behavior without realizing the privacy and integrity implications of outbound messaging and filesystem writes.
The cron example documents fully unattended daily execution and push behavior, but there is no explicit caution that the task will run automatically every day and continue sending/writing content until disabled. In practice, this can lead to persistent unwanted transmissions, spam to Telegram chats, and silent accumulation of files in user-managed directories.
The skill declares required binaries and environment variables but does not define an explicit permission/tool scope despite clearly describing capabilities that involve file writes, network access, environment secret use, shell/cron automation, and local path access. This is dangerous because users and orchestration systems cannot accurately constrain what the skill may do, increasing the chance of unintended secret access, network exfiltration, or filesystem modification beyond user expectations.
The natural-language description explicitly frames the skill as performing a 'forced cognitive reboot' and later requires a specific ideological analysis method as the default output style. This imposes a particular worldview/tone on generated content without describing user choice or opt-in, which is a natural-language policy concern.
The skill text does not prominently warn users that it writes to a fixed local path and may automatically push content to Telegram on a schedule. This is dangerous because silent local writes and unattended outbound messaging can surprise users, expose sensitive workspace structure, overwrite expected locations, or cause unintended automated publication.
This JSON configuration hard-codes Chinese-language paths and content/style values such as "每日语录" and "写实摄影风格,高清,有深度", indicating the skill is configured for a specific language/locale. Under the policy, locale-specific behavior should offer user choice or include a clear justification; neither is present in this file.
The manifest positions the skill as delivering '每日毛选语录' with Mao-selected quotations, but this data file contains '不管黑猫白猫,能抓老鼠的就是好猫。' attributed to 邓小平 rather than 毛泽东. If used by the skill, the actual delivered content would not consistently match the declared Mao-quote purpose.
This markdown template presents all user-facing headings and prompts exclusively in Chinese, such as the title and section labels. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.
The module description and prompt schema are written to generate output specifically in Chinese, and the skill does not present any opt-in or configurable language selection. This is a natural-language locale constraint that may violate policy when imposed without user choice or explicit justification.
The function sends quote text, source, and date to a third-party API without any consent gate, disclosure, or data classification check. In this skill, content may seem low sensitivity, but the implementation is generic and could forward unpublished, private, or regulated material to an external processor, creating privacy and compliance risk.
The module docstring, function descriptions, log messages, and CLI description are all written in Chinese, which establishes a fixed language experience for users. The file does not indicate that Chinese is optional or that the skill is intentionally region- or locale-specific, so this appears to violate the language/locale choice policy.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
logging.warning("未配置 Telegram BOT_TOKEN 或 CHAT_ID")
return False
url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
data = {
'chat_id': chat_id,
'text': message,
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
logging.warning("未配置 Telegram BOT_TOKEN 或 CHAT_ID")
return False
url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
data = {
'chat_id': chat_id,
'text': message,
This shell script presents all user-facing output in Chinese and instructs users to create a cron task with a Chinese task string, without offering any language or locale option. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
No suspicious patterns detected.