Telegram Plugin Updater
k1p1l0/claude-telegram-supercharged
Updates the enhanced Telegram plugin for Claude Code from its GitHub repository: compares file hashes, shows recent commits, asks first, then runs the installer.
Audit Telegram Desktop dependencies on freshly fetched origin/dev for releases and security fixes, including upstream lag and backport candidates in patched forks.
$ npx skills add telegramdesktop/tdesktop --skill dependency-watch -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install telegramdesktop/tdesktop dependency-watch --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/telegramdesktop/tdesktop.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dependency-watch .claude/skills/dependency-watch && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dependency-watch" agent skill from https://github.com/telegramdesktop/tdesktop/tree/dev/.agents/skills/dependency-watch into .claude/skills/dependency-watch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-watch", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/telegramdesktop/tdesktop/tree/dev/.agents/skills/dependency-watchType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add telegramdesktop/tdesktop --skill dependency-watch -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install telegramdesktop/tdesktop dependency-watch --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/telegramdesktop/tdesktop.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/dependency-watch .agents/skills/dependency-watch && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dependency-watch" agent skill from https://github.com/telegramdesktop/tdesktop/tree/dev/.agents/skills/dependency-watch into .agents/skills/dependency-watch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-watch", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add telegramdesktop/tdesktop --skill dependency-watch -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install telegramdesktop/tdesktop dependency-watch --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/telegramdesktop/tdesktop.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/dependency-watch .cursor/skills/dependency-watch && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dependency-watch" agent skill from https://github.com/telegramdesktop/tdesktop/tree/dev/.agents/skills/dependency-watch into .cursor/skills/dependency-watch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-watch", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/telegramdesktop/tdesktop.git --path .agents/skills/dependency-watch--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add telegramdesktop/tdesktop --skill dependency-watch -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install telegramdesktop/tdesktop dependency-watch --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/telegramdesktop/tdesktop.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/dependency-watch .gemini/skills/dependency-watch && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dependency-watch" agent skill from https://github.com/telegramdesktop/tdesktop/tree/dev/.agents/skills/dependency-watch into .gemini/skills/dependency-watch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-watch", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install telegramdesktop/tdesktop dependency-watchInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add telegramdesktop/tdesktop --skill dependency-watch -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/telegramdesktop/tdesktop.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/dependency-watch .github/skills/dependency-watch && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dependency-watch" agent skill from https://github.com/telegramdesktop/tdesktop/tree/dev/.agents/skills/dependency-watch into .github/skills/dependency-watch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-watch", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add telegramdesktop/tdesktop --skill dependency-watch -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install telegramdesktop/tdesktop dependency-watch --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/telegramdesktop/tdesktop.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/dependency-watch .opencode/skills/dependency-watch && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dependency-watch" agent skill from https://github.com/telegramdesktop/tdesktop/tree/dev/.agents/skills/dependency-watch into .opencode/skills/dependency-watch/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dependency-watch", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dependency-watchAudit Telegram Desktop dependencies on freshly fetched origin/dev for releases and security fixes, including upstream lag and backport candidates in patched forks.
Dependency Watch is an agent skill from telegramdesktop/tdesktop. Audit Telegram Desktop dependencies on freshly fetched origin/dev for releases and security fixes, including upstream lag and backport candidates in patched forks. Use for the daily dependency monitor or an explicitly requested dependency report.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/forks.md` and `references/release-trust.md`).
It sits in Productivity & Automation. It works with Telegram and Git. The repository describes itself as: Telegram Desktop messaging app. The licence is GPL-3.0.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 6fed91f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dependency Watch loads about 2.2k tokens when it runs, and up to ~4.8k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 1,173 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from telegramdesktop/tdesktop at commit 6fed91f, republished under its GPL-3.0 licence (© telegramdesktop). 1,173 words, ~2,233 tokens.
.claude/skills/dependency-watch/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Produce an advisory report about dependencies consumed by origin/dev. This
workflow does not bump dependencies, build Telegram, create queue records, commit,
push, open PRs, or apply backports. Those are separate implementation requests.
Run from the repository root:
python3 .agents/skills/dependency-watch/scripts/watch.py snapshotThe helper fetches only origin/dev, resolves it once, and reads Git blobs at
that exact commit without switching branches or touching working files. It
prints the snapshot directory and report storage root. A failed fetch is a
failed current check; do not present an older remote ref as freshly checked.
--no-fetch is for offline testing only and marks its snapshot as unverified.
Read snapshot.json, candidates.json, and the relevant files in sources/.
Candidates are navigation aids, not a complete parsed dependency inventory.
Inspect the full union of prepare, Docker, Snap, Qt selection, workflow and
package/lock files. Snapshot gitlinks and .gitmodules identify exact submodule
revisions; inspect their dependency declarations recursively, especially CMake,
WebRTC, codecs, and bundled image/font/compression/crypto libraries. Add newly
discovered dependencies on every run; never restrict coverage to yesterday's
list. Distinguish shipped libraries, system-provided components and build tools.
Read repository history at the snapshot commit to explain divergent pins and holds. Derive platform conditions from the recipes. A library disabled in one configuration can still be relevant on another platform. A source manifest does not establish what is installed or what already shipped to users.
Store research caches and reports in the helper's storage_root, inside Git's
common directory. Read its previous latest.json and latest.md when present.
Inspect external Git repositories through APIs or isolated caches there; do not
fetch, checkout, or reset the user's prepared libraries or live submodules.
Do not execute downloaded build scripts or import the prepare script to read it.
For every dependency record its identity, upstream, current version/revision, manifest locations, platform/configuration, release scheme and supported series. Fetch official release/tag metadata and release notes; check security advisories independently, including advisories published since a release. Search vendor security pages and GHSA/OSV/CVE sources as appropriate; native C/C++ projects may not have package identifiers in advisory databases. Absence from a database is not evidence of safety. Cite primary sources and dates for actionable claims.
Use watch.py compare CURRENT CANDIDATE for ordinary three-component stable
versions. It rejects prereleases and unsupported schemes as unknown; inspect
upstream version policy for those instead of forcing SemVer on commit hashes,
dates, Chromium milestones, OpenSSL legacy letters, or four-component versions.
For 0.x, also assess compatibility from upstream notes. Compare all maintained
release series we consume, not just the upstream API's single latest release.
Read release-trust.md before recommending any candidate. Track update urgency separately from the decision to update, backport, hold, skip, or track. A patch number sets a review priority; it does not establish release trust, compatibility, or readiness to adopt.
Rank findings as follows, subject to that assessment:
An intentional hold does not hide patch releases or security findings. Show the reason for the hold beside the recommendation. Deduplicate the same dependency across recipes, preserving different platform series and patch revisions. For distro-provided packages, check the distribution's full package revision, security tracker and backports. Record artifact/package resolution as unknown when unavailable; an old upstream version alone does not prove vulnerability. Track Docker base images, mutable package installs and Snap runtime/content snaps as separate update/rebuild concerns even when no source pin changed.
Read forks.md when checking patched or copied upstreams;
always apply it to tg_owt and tg_angle when present in the snapshot.
On the first audit establish a baseline across all discovered dependencies.
On subsequent runs reuse verified source mappings, imported revisions and
backport evidence, but refresh release/advisory metadata daily even if origin/dev
did not move. Recheck evidence when a pin, patch set, relevant code, upstream fix
or advisory changes. First inspect high-exposure libraries and existing urgent
findings, then finish the rest. Follow API pagination; conditional requests and
cached Git objects can reduce work without skipping unresolved history.
Maintain latest.json with the snapshot commit/time, per-dependency check times,
coverage (checked, partial, unavailable, or not-checked), current and
candidate versions, findings, source links, and fork evidence. Give each finding
a stable identity based on dependency, consumed series/platform and advisory or
target version. Record first/last seen and whether it remains pending. Preserve
pending findings across failures; only resolve them with evidence from the new
snapshot. A revision change alone does not prove that a fix was incorporated.
Persist each candidate's decision and reason, release date, assessed source
identity, trust/regression evidence, unknown checks, and next review date or
condition. A hold or skip does not resolve an outstanding security problem.
If access or time prevents full coverage, save a partial report naming the gaps and last successful checks. Never write "all up to date" after an incomplete scan. Record stale security coverage prominently when it affects pressing items. A first run may need substantial fork archaeology; keep its evidence and resume unresolved ranges next time instead of repeatedly starting over. A keyword scan of recent commit subjects does not complete a security review of an older tail.
Save report.md and findings.json beside that run's snapshot, then replace
latest.md and latest.json in the storage root using temporary files and atomic
rename. Preserve prior run reports. Date reports in Asia/Dubai and give the exact
origin/dev commit, fetch time, and whether the audit was complete or partial.
Use two main blocks, in this order:
Both blocks must be present, even when empty. End with a compact coverage line (checked/total, unavailable checks and oldest outstanding coverage). A scan of source declarations alone must not claim that distributed binaries are fixed. The scheduler decides when to post this report in the chat; the saved report always retains the complete pending list.
© telegramdesktop, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in .agents/skills/dependency-watch of telegramdesktop/tdesktop.
Open the folder on GitHubat commit 6fed91f
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in telegramdesktop/tdesktop, which our catalogue first saw on October 9, 2026.
Dependency Watch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dependency Watch this skilltelegramdesktop/tdesktop | 33k | 1 repos | ~2.2k | Automated safety check: Pass | GPL-3.0 | |
| Telegram Plugin Updaterk1p1l0/claude-telegram-supercharged | 132 | — | ~764 | Automated safety check: Pass | Apache-2.0 | |
| Process InboxTDesktop-x64/tdesktop | 3k | — | ~4.3k | Automated safety check: Pass | GPL-3.0 | |
| Telegrambubbuild/bub | 1.7k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Challenge Baseline ModelAgibotTech/genie_sim | 1.4k | — | ~2.4k | Automated safety check: Pass | Custom licence | |
| Keen Pbr Release Postmaksimkurb/keen-pbr | 141 | — | ~844 | Automated safety check: Pass | GPL-3.0 |
k1p1l0/claude-telegram-supercharged
Updates the enhanced Telegram plugin for Claude Code from its GitHub repository: compares file hashes, shows recent commits, asks first, then runs the installer.
TDesktop-x64/tdesktop
Process the local ignored ai-tdesktop inbox into durable, independently testable Telegram Desktop task records while task execution worktrees remain active.
bubbuild/bub
Telegram Bot skill for sending and editing Telegram messages via Bot API.
AgibotTech/genie_sim
Provision and launch the Simulation Challenge baseline inference model end to end: clone the inference code from a given git repo/branch, download the checkpoints from ModelScope into the repo's…
maksimkurb/keen-pbr
Draft keen-pbr release posts for GitHub and Telegram from git history.
pytdbot/client
Write Telegram bots and userbots with Pytdbot (async TDLib wrapper with high-level helpers; not the Telegram Bot API).
telegramdesktop/tdesktop
Resolve, start or resume, implement, review, test, and publish exactly one existing ai-tdesktop task by short slug or full dated id, including rare blocked retries and split-required results.
telegramdesktop/tdesktop
Continue autonomous Telegram Desktop development from the shared ai-tdesktop repository.
telegramdesktop/tdesktop
Process the local ignored ai-tdesktop inbox into durable, independently testable Telegram Desktop task records while task execution worktrees remain active.
telegramdesktop/tdesktop
Drive an intent-aware rebase of the current checkout, resolving every conflict by reading the history behind both sides instead of by making the markers disappear.
Categories
Audit Telegram Desktop dependencies on freshly fetched origin/dev for releases and security fixes, including upstream lag and backport candidates in patched forks. Dependency Watch is an agent skill from telegramdesktop/tdesktop. Audit Telegram Desktop dependencies on freshly fetched origin/dev for releases and security fixes, including upstream lag and backport candidates in patched forks.
Dependency Watch fits situations like: the daily dependency monitor; an explicitly requested dependency report.
Run `npx skills add telegramdesktop/tdesktop --skill dependency-watch -a claude-code`. Or copy the skill folder (.agents/skills/dependency-watch in telegramdesktop/tdesktop) into .claude/skills/dependency-watch in your project. Claude Code loads it when a task matches its description.
Run `npx skills add telegramdesktop/tdesktop --skill dependency-watch -a codex`. Or copy the skill folder (.agents/skills/dependency-watch in telegramdesktop/tdesktop) into .agents/skills/dependency-watch in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add telegramdesktop/tdesktop --skill dependency-watch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dependency-watch, .gemini/skills/dependency-watch, .github/skills/dependency-watch and .opencode/skills/dependency-watch in your project.
Going by SKILL.md and its folder, Dependency Watch needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Dependency Watch is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dependency Watch: Telegram Plugin Updater (k1p1l0/claude-telegram-supercharged, 132 stars), Process Inbox (TDesktop-x64/tdesktop, 3k stars), Telegram (bubbuild/bub, 1.7k stars) and Challenge Baseline Model (AgibotTech/genie_sim, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
telegramdesktop (a GitHub organization) maintains it in telegramdesktop/tdesktop, which has 33,193 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 10, 2026.
Source: telegramdesktop/tdesktop on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.