telegram-bot-builder

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate code templates and architectural guidance for developing Telegram bots using industry-standard libraries.
  • [CREDENTIALS_UNSAFE]: The code snippets demonstrate secure practices by using environment variables (process.env.BOT_TOKEN and process.env.PAYMENT_TOKEN) for sensitive API credentials instead of hardcoding them.
  • [INDIRECT_PROMPT_INJECTION]: The skill templates acknowledge user input processing (e.g., ctx.message.text), which is standard for chatbot functionality. The inclusion of anti-patterns advising against poor error handling encourages safer implementation by the end developer.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:33 PM
Security Audit — agent-trust-hub — telegram-bot-builder