Back to skill

Security audit

BlockBeats Monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it needs review because Telegram credentials are exposed through a spawned curl command while sending reports externally.

Install only if you are comfortable with BlockBeats content being stored locally and generated reports being sent to the configured Telegram chat. Protect config.toml, use a least-privileged Telegram bot, review report contents before sending, and prefer changing the Telegram sender to avoid putting the bot token in child-process command arguments.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/telegram.py:10
Finding

Telegram Bot Token Exposed in Child Process Command-Line Arguments

Content
View full analysis
/cmdline`, monitoring agents, audit systems, or process telemetry. Any principal with sufficient local process-observation access could therefore obtain the Telegram bot token while a message is being sent. Using HTTPS protects the credential while it is transmitted over the network, but it does not prevent this local command-line disclosure. The network operation itself is consistent with the Skill's declared Telegram reporting functionality; the vulnerability is specifically the avoidable exposure caused by invoking `curl` with the secret in i ...[truncated 1757 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a complete data-processing and reporting workflow involving content monitoring, categorization, database storage, and Telegram output. The supplied code chunk contains only a package initializer comment and no operational logic implementing any of those behaviors. This is therefore a material description-versus-code mismatch: the actual code does not exhibit the declared primary purpose or capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述的是一个完整的舆情监测与日报流水线:监听 BlockBeats 内容、按关键词组归类统计、存入 SQLite、生成 Telegram 日报。而实际代码片段只包含 BlockBeats 客户端层能力,即访问 API、提取列表、解析发布时间、标准化字段,并批量抓取若干 category。它没有实现关键词匹配/分类统计、数据库持久化、Telegram 报告生成或发送等核心声明功能。因此该代码片段的实际行为仅覆盖了声明中的“监听/采集 BlockBeats 内容”这一部分,未能准确代表完整声明目的,属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file explicitly instructs users to send generated reports to a Telegram group or channel, which transmits collected content to a third-party service. The README explains how to configure and run the push, but does not warn users about the external data transfer or advise them to review the report contents before sending.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises commands that perform shell execution, local file reads/writes, and outbound network access, but it does not declare any explicit tool scope such as permissions or allowed-tools. That omission weakens least-privilege controls and makes it harder for a host agent or reviewer to understand and constrain what the skill may do before execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill does say it stores data in SQLite and sends Telegram reports, but it does not present these as an explicit caution or prominent disclosure at the point where users decide to invoke it. Insufficient disclosure of persistence and third-party transmission can lead users to run the skill without understanding that collected content is retained locally and pushed to an external messaging platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The send-telegram command reads a local text file and sends its contents plus configured chat destination to Telegram, which is a network transmission of potentially sensitive user or system data. Although the command name implies sending, this file provides no confirmation prompt and no explicit warning comment/docstring near the operation about external transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The run-daily command performs collection, report generation, and network transmission to Telegram in one flow. While the subcommand help mentions Telegram, the code around the send operation lacks a visible warning or confirmation that report contents will be transmitted externally, which is relevant for privacy and data-handling awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file hard-codes DEFAULT_LANG = "cn" and DEFAULT_TIMEZONE = "Asia/Shanghai", establishing a specific language/locale behavior by default. Under the policy, forcing a specific language or locale without explicit user choice or a clearly documented region-specific justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This migration reads existing rows, then deletes all records from item_matches, item_sources, and source_items before reinserting merged data. Although the docstring describes the migration, there is no confirmation prompt, visible logging, or explicit user disclosure for this destructive rewrite of stored data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file’s natural-language comments and docstrings are entirely in Chinese, including operational descriptions such as the module purpose and function behavior. This indicates a locale-specific constraint in the skill’s instructions without any visible user choice or documented justification, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file comment and all user-facing report strings are written in Chinese, and the rendering logic always produces Chinese-language output. This forces a specific language/locale without any user opt-in or documented region-specific justification, which matches the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Comments and docstrings throughout the file are written exclusively in Chinese, which can impose a language constraint on maintainers or users without any opt-in or stated regional justification. The policy requires avoiding forced language or locale choices unless the constraint is documented and justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/telegram.py (reported line 20)May include surrounding context.

python
"-sS",
        "-X",
        "POST",
        "https://api.telegram.org/bot%s/sendMessage" % bot_token,
        "--data-urlencode",
        "chat_id=%s" % chat_id,
        "--data-urlencode",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/telegram.py (reported line 37)May include surrounding context.

python
"-sS",
        "-X",
        "POST",
        "https://api.telegram.org/bot%s/sendMessage" % bot_token,
        "--data-urlencode",
        "chat_id=%s" % chat_id,
        "--data-urlencode",

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/telegram.py (reported line 28)May include surrounding context.

python
"--data-urlencode",
        "disable_web_page_preview=true",
    ]
    completed = subprocess.run(command, check=True, capture_output=True, text=True)
    data = json.loads(completed.stdout)
    if not data.get("ok"):
        raise RuntimeError("Telegram 推送失败:%s" % data)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs an outbound HTTP POST to the Telegram Bot API and sends the provided chat ID and message text to an external service. Although the file comments describe the implementation, there is no user-facing confirmation, warning, or explicit disclosure about transmitting generated content off-system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The sample configuration sets lang = "cn", which indicates a fixed language/locale choice. Elsewhere the README does not offer an alternative language option or explain that the skill is intentionally limited to Chinese-language operation, so this appears to force a locale without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The lang = "cn" setting hard-codes a specific language/locale in the example configuration. This can violate language-choice policy when no user opt-in or alternative locale guidance is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file begins with a Chinese-only descriptive comment, which constitutes a natural-language locale choice embedded in the artifact. There is no indication that the skill is region-specific or that users can opt into this language, so it may violate the language/locale policy described for all file types.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The constructor sets lang="zh" by default, which imposes a specific language choice on all requests unless the caller overrides it. This is a natural-language policy concern because the file does not indicate user choice or an explicit justification for forcing a locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The function creates parent directories, opens the schema file, executes it, and inserts or updates keyword-group records, which modifies persistent local state. In this file there is only an internal docstring in Chinese and no confirmation prompt, print/log statement, or other user-facing disclosure around these write operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code contains natural-language comments and docstrings entirely in Chinese, including the top-level file description and function/class documentation. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy issue when no justification or language choice is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The function invokes an external program via subprocess to perform network transmission. While this is part of the implementation, the file provides no user-facing notice, prompt, or explicit warning that an external command will be executed.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/blockbeats_monitor.py:35