Back to skill

Security audit

Telegraph Protocol

Security checks across malware telemetry and agentic risk

Overview

This skill is purpose-aligned, but it can route user content to changing third-party AI providers and spend wallet funds through automatic paid calls with limited per-call user control.

Install only if you intentionally want Telegraph-routed inference and are comfortable sending prompts, images, video, or text to external miners/providers. Use a burner wallet with a very small balance, inspect the live miner catalog before sensitive requests, and avoid configuring a main wallet or submitting private data unless you trust the current provider path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation text is very broad, covering weather, climate, deepfake detection, LLM completions, embeddings, signal monitoring, and any task where the user wants Telegraph routing or x402 payments. In a skill that can trigger paid network calls and route prompts to external providers, broad matching increases the chance of unintended activation, accidental data disclosure to third parties, and unintended micropayment spending.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The dynamic miner tools are auto-discovered from a live registry and can forward prompts, images, text, and other payloads to third-party miners or APIs over the network, but the skill does not clearly foreground this privacy and data-transfer risk. Because the live tool set changes on-chain and may include hosted models or private APIs, users may unknowingly send sensitive content to external providers outside their trust boundary.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.