Check suspicious links via Telegram with GPT-4 analysis of VirusTotal & urlscan.io results
Transform a Telegram bot into a personal security guard by automatically vetting suspicious URLs through VirusTotal and urlscan.io. This workflow uses GPT-4 to interpret complex technical data into concise summaries, giving you clear guidance on whether a link is safe to click. It includes robust error handling to ensure you receive a security report even if one of the scanning services experiences a timeout.
Run this with your team's AIWhat This Recipe Does
Protecting your organization from malicious links is a critical component of modern cybersecurity. This automation provides a streamlined way to verify the safety of URLs shared within your team's communication channels. When a link is submitted via Telegram, the workflow automatically triggers a deep scan using industry-standard security intelligence. It analyzes the destination for phishing attempts, malware, and other digital threats in real-time. By centralizing this process, you eliminate the need for manual checks and reduce the risk of human error. The system logs all scan results in a Google Sheet for audit purposes and sends immediate alerts back to your team. This ensures that your staff can interact with digital content confidently, knowing that every link is being vetted against global security databases. For business owners and IT managers, this means a significantly lower risk of data breaches and a more proactive approach to organizational security without adding complex technical overhead.
What your team gets
Forms and dashboards, so it is not a script only one person understands
Runs on your schedule in the cloud, so it does not stop when a laptop closes
Endpoints, so the rest of your stack can trigger the same work
Telegram, Google Sheets connected for the team, not per person
How It Works
- 1
Open the recipe and connect your accounts
Connect Telegram and Google Sheets once, in your team cloud, and nobody has to do it again on their own machine
- 2
Tell your own agent what is different about your process
Claude, ChatGPT, Cursor, whichever your team already uses. It adapts the recipe to how you actually work
- 3
Run it, then leave it running
It lives in your team cloud, so it keeps going after you close the laptop and every teammate's AI can use it
Who Uses This
- Security teams who need to automate the screening of suspicious links reported by employees in real-time.
- IT managers who want to maintain a centralized log of all scanned URLs for compliance and auditing purposes.
- Remote teams using Telegram who require an instant, automated verification system to prevent phishing attacks.
Frequently Asked Questions
What information do I receive after a URL is scanned?
The system provides a comprehensive report including the safety status of the link, potential threat categories, and a record of the scan stored in your connected spreadsheet.
Can I use this with other messaging platforms besides Telegram?
While this specific recipe is optimized for Telegram, the core logic can be adapted to work with other communication tools like Slack or Microsoft Teams.
Do I need a paid account for the scanning service?
This automation integrates with UrlScan.io, which offers a free tier for a standard number of monthly scans, making it accessible for small to medium businesses.
How does this improve my team's security posture?
It creates a standardized, frictionless process for link verification, ensuring that security checks are performed consistently rather than relying on manual intervention.
Coming from n8n?
This recipe uses nodes like StickyNote, HttpRequest, Telegram, TelegramTrigger and 8 more. On Runwork, you don't need to learn n8n's workflow syntax. Describe what you want to your own AI agent in plain English.
Based on n8n community workflow. View original
Related Recipes
Monitor SSL certificate expiry dates with Google Sheets & Slack alerts
Maintaining secure websites is critical for customer trust and search engine rankings, yet many businesses rely on manual checks or memory to renew SSL certificates. This automation eliminates the risk of expired certificates by transforming a simple Google Sheet into a proactive monitoring system. The workflow automatically scans your list of domains on a set schedule, calculates the days remaining until expiry, and triggers instant alerts via Slack when action is needed. By centralizing your domain management, you avoid the chaos of managing multiple vendor portals and prevent costly downtime or security warnings that drive visitors away. This tool ensures your IT or security team has ample lead time to handle renewals, moving your infrastructure management from reactive firefighting to organized, automated oversight.
Analyze emails with S1EM
This automation streamlines your security operations by transforming a standard email inbox into a proactive incident response hub. By monitoring incoming messages via IMAP, the system automatically identifies potential threats and converts them into structured cases within TheHive. Instead of requiring security analysts to manually monitor mailboxes for phishing reports or system alerts, this workflow handles the entire intake process. It utilizes Cortex to perform deep analysis on suspicious indicators, such as URLs and file attachments, ensuring that your team has enriched, actionable data the moment they begin an investigation. The workflow includes intelligent logic and waiting periods to ensure all automated background checks are completed before finalizing the report. This approach significantly reduces the mean time to respond (MTTR) to security incidents by eliminating manual data entry and initial triage. By offloading these repetitive tasks to an automated system, your security personnel can focus on high-value remediation and strategic defense rather than administrative overhead. The result is a faster, more accurate security posture that ensures critical alerts are never missed in a crowded inbox.
Generate domain insights with WHOIS lookup and GPT-5-Nano via RapidAPI
This automation serves as a powerful bridge between your front-end applications and external security or identity verification services. By utilizing a webhook-based architecture, it allows your business to securely process incoming data requests, perform complex HTTP lookups, and return immediate, structured responses. This is particularly valuable for organizations that need to validate user credentials, check identity status, or interface with third-party security APIs without building a custom backend from scratch. Instead of manual verification processes or fragmented data handling, this workflow centralizes the logic, ensuring that every request is handled consistently and securely. The result is a more responsive user experience, reduced manual overhead for security teams, and a scalable way to manage identity-related data across multiple platforms. By automating the communication between your app and external data sources, you ensure that critical security information is always accurate and delivered in real-time to the systems that need it most.
Protect Telegram groups with math CAPTCHA verification and Google Sheets
The Security and Identity Management automation provides a robust framework for handling sensitive user interactions and data verification directly through Telegram. By integrating messaging capabilities with Google Sheets and custom logic, this workflow transforms a standard chat interface into a secure portal for identity management. It eliminates the need for complex internal portals by allowing administrators or automated systems to process requests, verify information against existing databases, and update records in real-time. The automation ensures that every interaction is logged and validated, reducing the risk of unauthorized access or data entry errors. For businesses handling high volumes of user requests or requiring rapid identity verification, this solution provides a scalable way to maintain security protocols without sacrificing speed. It bridges the gap between communication platforms and core data management, ensuring that your identity workflows are both accessible and highly secure.
Run this with the AI your team already uses
Your agent adapts it, your team cloud keeps it running, and everyone's AI can find it.
Open this recipe in Runwork