telegram-group-analytics-bot
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSOBFUSCATIONPRIVILEGE_ESCALATIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to download a "release package" and clone code from an untrusted GitHub repository (
github.com/ddperso/Telegram_Group_Statistics___Analytics_Bot.git) that is not affiliated with a known trusted organization. - [OBFUSCATION]: The installation instructions require extracting a package using a password (
trainer2026). Password-protected files are a common tactic used to hide malicious content from automated antivirus and EDR (Endpoint Detection and Response) scanners. - [PRIVILEGE_ESCALATION]: The skill explicitly directs the user to "Run
setup.exeas Administrator". Granting administrative rights to an unverified binary from an untrusted source allows for full system compromise and unauthorized persistence. - [REMOTE_CODE_EXECUTION]: The combination of downloading external binaries, bypassing scanners via password protection, and requesting elevated privileges creates a significant risk for the execution of arbitrary malicious code on the user's host system.
Recommendations
- AI detected serious security threats
Audit Metadata