telegram-reader

Fail

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill's setup instructions in SKILL.md suggest installing the core dependency via curl -sSL https://docs.iyear.me/tdl/install.sh | sudo bash. Piped execution of remote scripts is a high-risk pattern, especially when targeting a domain outside the trusted list.
  • [PRIVILEGE_ESCALATION]: The recommended installation method involves sudo bash, which provides the remote script with administrative access to the system.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes messages from Telegram channels, which are untrusted external sources.
  • Ingestion points: Telegram messages are exported to a temporary file (/tmp/tdl-export.json) and then processed by the agent.
  • Boundary markers: The skill does not define clear delimiters or provide instructions for the agent to ignore potentially malicious embedded content within messages.
  • Capability inventory: The agent can execute tdl commands and standard shell utilities.
  • Sanitization: There is no evidence of message content sanitization or filtering before the agent processes it.
  • [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file employs dynamic context injection (!command) to check the installation and authentication status of the tdl tool during skill loading. While these specific checks for version and login status are benign, the mechanism itself represents a significant capability that executes before user review.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 26, 2026, 12:30 PM
Security Audit — agent-trust-hub — telegram-reader