telegram

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
.mcp.json

No direct malware is evident in the configuration fragment itself; it simply configures an MCP server to launch a Telegram connector via `npx -y`. The primary concern is supply-chain execution risk: an unpinned third-party npm package is resolved and potentially downloaded/executed at runtime/non-interactively. Mitigate by pinning an explicit connector version, using lockfiles and/or integrity verification, and ensuring the MCP runner executes dependencies only from trusted, reproducible sources.

Confidence: 60%Severity: 60%
Audit Metadata
Analyzed At
Aug 24, 2026, 02:43 PM
Package URL
pkg:socket/skills-sh/zapier%2Fconnectors%2Ftelegram%2F@5f553adeb3399be3310d30f1f070426700dbcfa22009393486f46500db015f98
Security Audit — socket — telegram