telegram-polling

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Telegram integration is coherent and uses official Telegram endpoints, but the skill’s footprint goes beyond simple polling: it permits remote agent task creation/control and processes untrusted Telegram files/messages through agent workflows with Bash/Python execution. Security controls are substantial and purposeful, so this is not malicious, but it is a medium-high risk infrastructure skill due to autonomous task control and prompt-injection exposure.

Confidence: 88%Severity: 63%
Audit Metadata
Analyzed At
Mar 22, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/oimiragieo%2Fagent-studio%2Ftelegram-polling%2F@9ad1458284793e2ac83b3550a434be5c4bedf359