forward-message

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches the capability, and there is no obvious exfiltration proxy or unrelated credential grab. However, the skill's core action relies on an unverifiable local CLI script with access to a sensitive Telethon session, and it enables outbound message forwarding plus self-modification. This is coherent but high-trust and should be treated as risky rather than benign.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fforward-message%2F@28be5d8417b7fe725481505741a14fd6b77b3693