telegram-readonly

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/setup-and-safety.md

The documentation describes a read-only wrapper around a high-privilege Telegram session. The main security concerns are improper protection of the API credentials and the locally stored session string in config.json. While the wrapper limits exposed actions, the persisted session string and config file permissions are the primary risk vectors. To improve security, enforce strict file permissions, consider optional encryption or secure storage for the session string, and adopt explicit access controls and auditing for the credentials path. Supply-chain risk remains moderate due to reliance on Telethon and local credential handling; ensure repository code path cannot silently elevate to write actions.

Confidence: 65%Severity: 62%
Audit Metadata
Analyzed At
May 15, 2026, 09:45 AM
Package URL
pkg:socket/skills-sh/ropl-btc%2Fagent-skills%2Ftelegram-readonly%2F@7826d7f1b4ef0d4f6ab269313be771554c9f0dab
Security Audit — socket — telegram-readonly