Telegram Premium Features

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only guide for building subscription, payment, analytics, and pricing features, with expected privacy and payment risks but no hidden execution behavior.

Install this only as a reference guide for subscription and payment feature design. Before using the examples in a live product, add explicit consent for renewals and analytics, pseudonymize or minimize user identifiers, verify payment webhooks, use least-privilege provider keys, keep audit logs, define refund controls, and run legal/privacy review for billing, tax, and regional compliance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The analytics call records a persistent identifier (`user_id`) together with conversion behavior and experiment assignment, which creates linkable behavioral profiling without any visible minimization, consent, or disclosure in this file. In a subscription and pricing context, this can expose sensitive commercial behavior and create privacy/compliance risk if telemetry is broadly accessible, retained too long, or shared downstream.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal