telegram

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent with its stated purpose and uses an official registry-backed CLI from the same vendor ecosystem, so it does not look malicious. However, all Telegram access and authentication are mediated through Membrane rather than direct Telegram APIs, creating an intermediary data flow and credential-handling trust dependency; combined with mutable latest-version installs, this makes it medium risk rather than benign.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
May 1, 2026, 03:42 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftelegram%2F@579357a76295092296963fa5f8ae49005cbe8c40