telegram-copilot-build — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited telegram-copilot-build (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Build the Telegram + Ollama copilot as a thin adapter over the existing tdmcp local copilot. Telegram receives messages; Ollama decides responses/tool calls; tdmcp executes through the curated local tool registry and the TouchDesigner bridge.
Read these before changing code:
CLAUDE.mdsrc/llm/agent.tssrc/llm/client.tssrc/llm/tools.tssrc/cli/ask.ts and/or src/cli/chat.tssrc/utils/config.tsdocs/reference/cli.md and docs/reference/environment.md if CLI/env/docsare in scope
runAgentTurn, LlmClient, resolveTools, and existing TDMCP_LLM_*config wherever possible.
because they imply public HTTPS infrastructure.
TDMCP_BRIDGE_TOKEN guidance for anyreal venue or untrusted network.
headers.
Implement these before enabling mutating tools:
safe is default; standard and creative are explicit.pending action and expire or cancel cleanly.
a queue.
/cancel and /panic behavior. Cancel should stop pending model/action work;panic should route to the existing tdmcp safety path when available or provide the precise manual fallback.
fetch.getUpdates with offset tracking and sendMessage./status/safe/standard/creative/approve/cancel/panicChatMessage[] shape.runAgentTurn with the selected tool tier.AgentEvent into Telegram-friendly progress messages.allows immediate execution for that chat/tier.
them safe and audited.
Each builder writes a note under _workspace/telegram-copilot/:
UNVERIFIED;Should trigger:
Should not trigger:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.