tgcli

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated Telegram-management purpose and routes data to Telegram rather than a third-party proxy, but it installs a personal-account messaging CLI from a personal GitHub module using mutable @latest and grants the agent the ability to send messages/files as the user. This is not confirmed malware, but it carries meaningful supply-chain, credential-handling, and real-world action risk.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Mar 31, 2026, 11:02 PM
Package URL
pkg:socket/skills-sh/TechNickAI%2Fopenclaw-config%2Ftgcli%2F@cf18555d476e2713c98553a349659acc1249b850