Back to skill

Security audit

Telegram Alert Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a Telegram trading-alert guide, but its activation wording is broader than its stated purpose and could cause messages or alert content to be sent to Telegram in unintended situations.

Install only if you intend to send trading alerts to a specific Telegram chat or group. Avoid using it for general messaging, email/SMS, bulk communication, or sensitive content unless you explicitly want that content sent through Telegram and possibly retained in local alert history.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill's invocation scope is framed broadly around generic messaging, notification pushing, email/SMS, and communications integration, which can cause an agent to over-select this skill for unrelated user requests. In an agentic environment with `exec`, `write`, and external messaging capabilities, ambiguous routing increases the risk of unintended data transmission to Telegram or misuse for broader communication tasks than the user intended.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The capability coverage section defines a catch-all keyword set including fragmented and generic phrases such as messaging, notifications, communications integration, developers, teams, and automation workflows. This can make the skill activate in situations far outside its stated purpose, increasing the chance that an agent sends information to Telegram or performs local execution/storage actions when a narrower, safer skill would be more appropriate.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill describes sending alert content to Telegram and storing alert history locally, but it does not prominently warn users that message contents leave the local environment and that records may persist on disk. In practice, users may provide trading signals, identifiers, or other sensitive operational data without realizing it will be transmitted to a third-party service and retained locally, creating confidentiality and privacy risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.