Back to skill

Security audit

Telegram聊天管理器

Security checks across malware telemetry and agentic risk

Overview

This Telegram skill is mostly documentation, but it asks for broad read/write/command authority and describes generic automation capabilities without clear limits or consent controls.

Review before installing. Use this only when you intentionally want an agent to manage Telegram-related bot/chat tasks, and do not allow shell commands, file writes, or outbound API calls unless you have reviewed the exact action and the Telegram bot token/chat scope being used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description is overly broad and mixes unrelated use cases such as project management, workflow automation, and generic Telegram functionality. In an agent ecosystem, vague triggering criteria can cause the skill to be selected in contexts where users did not intend Telegram actions, increasing the chance of unnecessary external communication or tool use.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises file handling, API integration, information retrieval, and command execution, but does not present prominent user-facing warnings or consent requirements for these sensitive capabilities. This can mislead users and downstream agents into invoking operations that write files, execute commands, or contact external services without clear disclosure or approval.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.