telegram-reader
Fail
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_CONTEXT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill's setup instructions in SKILL.md suggest installing the core dependency via
curl -sSL https://docs.iyear.me/tdl/install.sh | sudo bash. Piped execution of remote scripts is a high-risk pattern, especially when targeting a domain outside the trusted list. - [PRIVILEGE_ESCALATION]: The recommended installation method involves
sudo bash, which provides the remote script with administrative access to the system. - [INDIRECT_PROMPT_INJECTION]: The skill processes messages from Telegram channels, which are untrusted external sources.
- Ingestion points: Telegram messages are exported to a temporary file (/tmp/tdl-export.json) and then processed by the agent.
- Boundary markers: The skill does not define clear delimiters or provide instructions for the agent to ignore potentially malicious embedded content within messages.
- Capability inventory: The agent can execute tdl commands and standard shell utilities.
- Sanitization: There is no evidence of message content sanitization or filtering before the agent processes it.
- [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file employs dynamic context injection (
!command) to check the installation and authentication status of the tdl tool during skill loading. While these specific checks for version and login status are benign, the mechanism itself represents a significant capability that executes before user review.
Recommendations
- AI detected serious security threats
Audit Metadata