🦞 UzStartup Coach

Security checks across malware telemetry and agentic risk

Overview

This is a transparent Telegram startup-coaching skill with disclosed local storage and consent-gated reminders.

Install only if you are comfortable using a Telegram bot for startup coaching. Use a dedicated Telegram bot token, avoid uploading confidential business documents unless needed, and use `/mydata` or `/deletedata` to review or remove stored local context. Broad words like "coach" or "mentor" may trigger the skill accidentally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes generic terms such as "start," "coach," "mentor," and variants that may appear in normal conversation, increasing the chance the skill activates when the user did not intend to invoke it. In a Telegram context, unintended activation can expose uploaded files to review flows, initiate data collection, or begin consent/persistence logic unexpectedly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal