telegram-bot-api-business-connections-and-suggested-posts

Warn

Audited by Snyk on Mar 7, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly lists event types and API surface such as "business_message", "edited_business_message", and business read/delete/profile methods, indicating the agent will ingest and act on untrusted Telegram user-generated messages as part of its workflow, which could carry indirect prompt-injection risk.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 7, 2026, 01:03 PM