telegram-automation

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This SKILL.md is functionally coherent: capabilities match the stated purpose of automating Telegram via a Telegram bot. The primary security concern is that it centralizes execution and credential handling through a third-party MCP (https://rube.app/mcp). That requires trusting the MCP with the Telegram Bot Token and message/media payloads. The skill dynamically loads tool schemas from the MCP, increasing the potential attack surface (remote behavior/control). There is no embedded malicious code in this document itself, but the credential-forwarding and reliance on an external managed service without documented protections create a meaningful supply-chain and credential-exfiltration risk. Recommend treating this as potentially vulnerable: only use with a vetted/trusted MCP, verify how tokens are stored/used, and prefer direct, auditable integrations to Telegram when possible.

Confidence: 75%Severity: 55%
Audit Metadata
Analyzed At
Feb 28, 2026, 05:45 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Ftelegram-automation%2F@3e21c2dfe8f11f97c5213e68a14cd35c748e7fb0