skills/gramiojs/documentation/gramio/Gen Agent Trust Hub

gramio

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes helper scripts that fetch data from the official Telegram domain (t.me) and the NPM registry (registry.npmjs.org) to verify username availability and retrieve package version metadata.
  • [COMMAND_EXECUTION]: The skill uses local Node.js scripts to perform project introspection and version detection. These tools assist the agent in providing accurate, version-specific advice based on the user's installed environment.
  • [INDIRECT_PROMPT_INJECTION]: The documentation provides comprehensive guidance on handling untrusted input from Telegram users, such as deep-link payloads and message text. It identifies deep-link payloads as untrusted input and recommends validation and sanitization, which is consistent with the primary purpose of a bot framework documentation skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:58 AM
Security Audit — agent-trust-hub — gramio