Back to sundial-org/awesome-openclaw-skills
critical
awesome-openclaw-skills / idea
https://skillshield.getunbound.ai/skill/13836High Risk & Threats
Launch background Claude sessions to explore and analyze business ideas. Say 'Idea: [description]' to trigger.
Findings (4)
Findings Preview
EX-003
Unguarded external data exfiltration via Telegram
Skill instructs sending research files to Telegram Saved Messages (lines 18, 32, 118) and queuing notifications to external chat (lines 69-70). The agent is directed to exfiltrate analysis results to an external messaging platform without explicit user approval per action. Combined with the shell script execution (which is unvetted), this creates an unguarded path from arbitrary command execution to external data transmission. The skill normalizes sending files externally as part of normal workflow.
Category Breakdown
Data Exfiltration
15
Malware & Persistence
10
Prompt Injection
25
Destructive Actions
20
Excessive Permissions
100
Supply Chain
30
Obfuscation
100