Back to skill

Security audit

Telegram Toolkit Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a Telegram bot setup guide with expected API examples and no hidden install or background behavior.

Install only if you intend to let an agent help build or configure a Telegram bot. Use a test bot token first, avoid pasting production secrets into shared logs, and review any curl or Python command before running it because some examples can send data to Telegram or change bot settings.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
79% confidence
Finding
The examples instruct users to perform real network requests carrying bot credentials and operational data to Telegram without an explicit warning that secrets and message contents are being transmitted externally. In an agent setting with exec capability, users may paste real tokens into commands and unintentionally expose credentials or send unintended messages.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.