Telegram Discord Bot Dev

Security checks across malware telemetry and agentic risk

Overview

This is a small documentation-only skill for scoping Telegram and Discord bot projects, with minor privacy and trigger-word caveats but no code or hidden access.

Before installing, note that the skill may activate on a broad Cantonese phrase for making a bot, and any real bot built from its advice should handle analytics, user behavior data, bot tokens, trading features, and public posting permissions with explicit user consent and separate code review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrase "整Bot" is very broad and likely to appear in ordinary conversation, which can cause the skill to activate unintentionally. This increases the chance of unsolicited sales-style responses, incorrect routing, or accidental invocation in contexts where the user did not explicitly request this skill.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises analytics and user-behavior tracking without any warning, consent language, or privacy limitation. That can lead users to disclose or permit collection of behavioral data without understanding tracking implications, creating privacy and compliance risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal