telegram-group-analytics-bot

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSOBFUSCATIONPRIVILEGE_ESCALATIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to download a "release package" and clone code from an untrusted GitHub repository (github.com/ddperso/Telegram_Group_Statistics___Analytics_Bot.git) that is not affiliated with a known trusted organization.
  • [OBFUSCATION]: The installation instructions require extracting a package using a password (trainer2026). Password-protected files are a common tactic used to hide malicious content from automated antivirus and EDR (Endpoint Detection and Response) scanners.
  • [PRIVILEGE_ESCALATION]: The skill explicitly directs the user to "Run setup.exe as Administrator". Granting administrative rights to an unverified binary from an untrusted source allows for full system compromise and unauthorized persistence.
  • [REMOTE_CODE_EXECUTION]: The combination of downloading external binaries, bypassing scanners via password protection, and requesting elevated privileges creates a significant risk for the execution of arbitrary malicious code on the user's host system.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — telegram-group-analytics-bot