telegram-send

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose and capabilities mostly align for a Telegram bulk-send skill, and visible data flows are to Telegram rather than an unrelated intermediary. However, it grants an AI agent the ability to perform bulk outbound messaging using local session credentials, which is a high-impact real-world action and only partially bounded by dry-run/test flags. No strong malware indicators are visible, but the skill carries meaningful operational and credential-handling risk.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
May 20, 2026, 03:08 PM
Package URL
pkg:socket/skills-sh/aaaaqwq%2Fclaude-code-skills%2Ftelegram-send%2F@749f5e1177773f257f0cc296b27b57595f3bd8f2
Security Audit — socket — telegram-send