add-telegram

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill purpose is coherent: it adds Telegram channel support and provides an end-to-end setup flow. However, the integration relies on merging code from an external GitHub repository, introducing a transitive trust boundary and supply-chain risk that is not mitigated by a trusted registry provenance. The credential handling (Telegram bot token) is standard, but token exposure risk exists if logs or insecure file permissions are present. Data flows to Telegram APIs are appropriate for the stated purpose. Overall risk is elevated primarily due to the external code merge (transitive install) and potential for hidden behaviors within the injected Telegram integration. Recommend tightening supply-chain practices (pin to a verified fork, include checksums, or vendor-signed code), and ensure strict secret handling and access controls.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 02:36 PM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw%2Fadd-telegram%2F@4b8f83a9de23c1ed9cfe79afb186505c5e1d4124