Notify Bot
Security checks across malware telemetry and agentic risk
Overview
This skill openly sends user-supplied messages to Telegram bots using locally stored bot tokens, which matches its stated purpose but should be used carefully.
Install only if you want agents to send Telegram messages using your stored bot tokens. Use limited-purpose bots, send only non-sensitive task text or opaque job IDs, and verify group/topic IDs before use because messages may remain visible to group members.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
