I have not joined the discord server, I have not paid for the program, I have not used the program. I am doing this is a completely clean and secure VM that only has access to the internet to try and keep it as clean of environment as possible. I am not being paid to do this, or getting any benefit from doing this whatsoever.
I have been talking with the author via PM to see if I can replicate the security concerns using very simple and benign code. Though the author has asked me not to disclose one of the libraries they use, they have disclosed publicly that they use ImageDetection2015. The other library makes complete sense to access and edit the registry. In the original coding of the library, it is completely safe and does not do anything nefarious.
So here are my findings with talking with the developer and trying to recreate the security concerns on the previous page:
As for the virus: It is an autoit script. Any exe that is built by autoit, even if it does absolutely nothing, will get flagged as a virus. It's a false positive.
As for the keylogger: It pushes buttons and makes mouse clicks. Even pushing a single button will have it marked as a keylogger.
As for the certificate store: I have searched through the scripting of the components the author uses and see no mention of "HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\AUTHRO OT\CERTIFICATES" in the code at all.
And finally, the proxy settings: I also do not see any mention about modifying "HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\IN TERNET SETTINGS".
I have asked the author if they are willing to send me the scripting for the bot itself. In the mean time, I do believe that the bot is safe to use and does not have anything intentionally nefarious about it. But as always, if you do use it, or any program for that matter, you are taking a risk. I really believe the risk is small at this point.