telegram

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
agents/openai.yaml

The fragment describes a legitimate Telegram notification and approval integration, not apparent malware. It contains a material command-injection risk in the declared curl command because JSON_PAYLOAD is interpolated into a shell single-quoted string without demonstrated escaping. Token handling and outbound operational-data transmission also require review of the missing implementation. The referenced npm package cannot be assessed from this YAML alone.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 04:00 AM
Package URL
pkg:socket/skills-sh/harshsinghmp%2Fmuse-skills%2Ftelegram%2F@216edcf98a18375bc9ae0dcda8a38ccae03682c31cfbf8040a6464cd64f8aa43
Security Audit — socket — telegram