telegram-crabbox-e2e-proof
Warn
Audited by Socket on May 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core behavior is mostly coherent for Telegram E2E QA, but the footprint is broader than a simple review helper: it uses a real leased user account, supports arbitrary remote shell commands, performs external messaging/publication, and fetches TDLib from an HTTP URL. The strongest concern is install/execution trust for the remote TDLib archive; the rest is high-impact but purpose-aligned QA automation.
Confidence: 84%Severity: 74%
Audit Metadata