telegram-inbound-run

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for a Telegram-to-CRM workflow, but it relies on unverifiable local executable scripts and performs consequential actions (CRM updates, notifications, git commits) without documenting provenance or exact network endpoints. No clear credential theft or malicious exfiltration is shown, so this is not confirmed malware, but execution trust and operational risk are materially elevated.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 20, 2026, 02:25 PM
Package URL
pkg:socket/skills-sh/aaaaqwq%2Fclaude-code-skills%2Ftelegram-inbound-run%2F@ad529baccd4a8eebaf720b6baa472da5023c5e8c
Security Audit — socket — telegram-inbound-run