T09 · Insecure Skill Coding Practices
- Location
scripts/telegram.py:10- Finding
Telegram Bot Token Exposed in Child Process Command-Line Arguments
- Content
View full analysis
/cmdline`, monitoring agents, audit systems, or process telemetry. Any principal with sufficient local process-observation access could therefore obtain the Telegram bot token while a message is being sent. Using HTTPS protects the credential while it is transmitted over the network, but it does not prevent this local command-line disclosure. The network operation itself is consistent with the Skill's declared Telegram reporting functionality; the vulnerability is specifically the avoidable exposure caused by invoking `curl` with the secret in i ...[truncated 1757 chars]- Remediation
View remediation
