telegram-mini-app

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the skill's footprint appears coherent with its stated purpose: building Telegram Mini Apps with TON integration and monetization. Data flows hinge on legitimate APIs (Telegram Web App, TON Connect) and standard web app deployment patterns. No obvious credential harvesting, unattended data exfiltration, or unverifiable binaries are present in the provided fragments. Some placeholder configuration (provider_token) should be wired securely in real deployments. The risk profile is LOW to MEDIUM, primarily driven by the involvement of crypto-related monetization and wallet interactions, which require proper user consent and secure handling but are not inherently malicious in this context.

Confidence: 98%Severity: 30%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:15 AM
Package URL
pkg:socket/skills-sh/claudiodearaujo%2Fizacenter%2Ftelegram-mini-app%2F@7ac2b6c8ceabdb2ae113412b855b45cfb3377ede