Back to skill

Security audit

herder-telegram

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Telegram-to-terminal-agent bridge with meaningful power, but its behavior is coherent with its stated purpose and includes practical limits.

Install this only if you intend Telegram users connected to your gateway to be able to start and steer local CLI agents. Prefer the Herdr pane flow for visibility and auditability, and use the headless shortcut only for simple one-shot prompts with agent binaries you already trust.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill explicitly expands from pane mediation into a headless execution mode that runs an arbitrary agent binary directly with user-supplied prompt text. That broadens the trust boundary and bypasses the Herdr isolation/visibility model described elsewhere in the skill, making it easier to trigger unintended direct execution paths and reducing auditability of what was run.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The documented command allows direct execution of whatever installed agent binary is selected, outside Herdr, with user-controlled input embedded in the invocation. Even though it is presented as a convenience feature, it authorizes a broader execution capability than the stated Telegram-to-Herdr pane-control purpose and may let operators bypass the safeguards, state tracking, and cleanup constraints applied to panes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.