telegram
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose matches Telegram automation, and the npm-based CLI appears to be the publisher's documented tool, so this is not overt malware. The main concern is data-flow integrity: Telegram access is mediated through ClawLink, which stores provider credentials server-side and receives user data/actions instead of using Telegram's official API directly from the agent.
Confidence: 84%Severity: 58%
Audit Metadata