Back to skill

Security audit

Tg Bot Builder Free

Security checks across malware telemetry and agentic risk

Overview

This looks like a Telegram bot-building helper, but its broad activation wording combined with write and command-execution permissions makes it worth reviewing before install.

Review this skill's activation criteria before installing. It is not showing evidence of exfiltration or destructive behavior, but allow it only for Telegram bot work and confirm any file writes, package installs, curl webhook calls, ping tests, or deployment commands before they run. Keep Telegram bot tokens in environment variables or ignored .env files as the skill recommends.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
79% confidence
Finding
The activation wording is broad enough to match general code generation, debugging, or deployment requests beyond Telegram bot construction. In an agent environment with read/write/exec tools, ambiguous routing can cause this skill to activate in unrelated contexts and generate or execute actions under an over-privileged toolset, increasing the chance of unintended side effects.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The declared capability coverage contains an excessively broad keyword list, including fragmented and generic terms, which can trigger unintended matching. In a skill that exposes exec/write capabilities, overmatching is dangerous because unrelated user requests may be routed into a tool-enabled workflow that can modify files or run commands without a sufficiently specific mandate.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.