Telegram Ui
Security checks across malware telemetry and agentic risk
Overview
The plugin's code, docs, and runtime instructions are coherent: it only needs a Telegram bot token/chat id and performs the UI actions (buttons, reactions, pin/unpin, location, dice) it describes; there are no unrelated secrets or external endpoints beyond the Telegram Bot API.
This plugin appears to do what it says: it will use your Telegram bot token/chat id (auto-detected if you have a Telegram channel configured) to send messages, inline buttons, reactions, pins/unpins, locations, and dice. Before installing: (1) confirm the bot token you plan to use and that the bot has required permissions (ability to send messages, pin messages, and — for reactions — Bot API ≥ 7.0), (2) be aware that certain user prompts (per SKILL.md) will cause the agent to run a full self-test sequence that performs multiple actions in your chat, and (3) if you want to audit the behavior, the plugin source is present in the package (no hidden network endpoints). If you don't want background activity, do not enable the plugin or disable it in your OpenClaw config.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
