telegram-notify-hardened
Pass
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTIONNO_CODE
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to send data to the official Telegram Bot API endpoint (api.telegram.org). The instructions include a specific security guardrail limiting network transmissions exclusively to this domain to prevent data exfiltration to unauthorized third-party services.
- [PROMPT_INJECTION]: The accompanying SAFETY.md file provides a detailed log of adversarial testing, including examples of prompt injection and social engineering attempts. These examples are documented for safety auditing purposes and are not active instructions for the agent.
- [NO_CODE]: The skill package contains no source code files or binaries; it operates entirely through natural language instructions and configuration defined in markdown files.
Audit Metadata