Back to skill

Security audit

Telebiz Mcp

Security checks for vulnerabilities and agentic risk

Overview

This Telegram integration is purpose-aligned, but it exposes a logged-in Telegram account through unauthenticated local network services that could be abused.

Review carefully before installing or running. This skill can read, send, forward, delete, and organize Telegram content using your logged-in browser session. Do not run it on a shared or untrusted machine or network unless the HTTP and WebSocket services are bound to loopback, protected with strong authentication, wildcard CORS is removed, destructive actions require confirmation, and vulnerable dependencies are updated.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/http-server.ts:197
Finding

Unauthenticated Network-Accessible Telegram MCP API

Content
View full analysis
{ log(`HTTP server listening on port ${HTTP_PORT}`); log(`MCP endpoint: http://localhost:${HTTP_PORT}/mcp`); log(`Status endpoint: http://localhost:${HTTP_PORT}/status`); log('Waiting for browser to connect to telebiz-mcp...'); }); ``` ### Technical Analysis The `/mcp` endpoint forwards caller-controlled JSON-RPC methods and parameters to the MCP subprocess without authenticating the caller or authorizing the requested tool. Calling `server.listen(HTTP_PORT)` without a host normally binds the service to all available interfaces, not only localhost. This conflicts with the log output and documentation, which present the endpoint as local. In addition, `Access-Control-Allow-Origin: *` permits requests from arbitrary browser origins where the browser's local-network security policy allows them. The exposed MCP tool set includes operations that read private messages and perform destructive or externally visible actions, such as sending messages, forwarding messages, deleting messages, deleting chats, re ...[truncated 1477 chars]
Remediation
View remediation
{ // ... }); ``` 2. Prefer a Unix domain socket when only local processes require access. 3. Require a cryptographically random bearer token for every MCP request. 4. Compare authentication values using a timing-safe comparison. 5. Remove wildcard CORS. Reject browser origins by default or allow only a narrowly configured trusted origin. 6. Validate both `Host` and `Origin` headers. 7. Implement a server-side tool allowlist and per-tool authorization. 8. Require explicit user confirmation for destructive tools. 9. Return proper HTTP 401 and 403 responses for unauthenticated and unauthorized requests. 10. Document that non-local exposure requires TLS, network filtering, and strong client authentication. ]]>

T07 · Tool Hijacking and Spoofing

Error
Location
src/relay.ts:137
Finding

Unauthenticated WebSocket Relay Allows Tool Invocation and Executor Replacement

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/daemon.ts:140
Finding

Legacy Daemon Exposes Unauthenticated Arbitrary Telegram Tool Calls

Content
View full analysis
body += chunk); req.on('end', async () => { try { const { tool, args } = JSON.parse(body); const result = await callTool(tool, args || {}); res.end(JSON.stringify({ success: true, result })); ``` The service listens without a host restriction: ```ts server.listen(PORT, () => { log(`HTTP API listening on port ${PORT}`); }); ``` ### Technical Analysis The daemon accepts a caller-controlled tool name and arguments through the `/call` endpoint and passes them to `callTool` without authentication, authorization, or a tool allowlist. Because `server.listen(PORT)` does not explicitly select a loopback address, the daemon may be reachable through external network interfaces. Although this daemon is not the primary startup path documented in `start-http.sh`, it is shipped as executable project functionality and exposes port 9717 when launched. The compiled implementation in `dist/daemon.js` contains the same behavior. ### Attack Path 1. A user or service manager launches the daemon. 2. The daemon starts an MCP subprocess and listens on port 9717. 3. An attacker with network reachability submits a request such as: ```http POST /call HTTP/1.1 Host: victim:9717 Content-Type: application/json {"tool":"sendMessage","args":{"chatId":"TARGET","text":"ATTACKER-CONTROLLED MESSAGE"}} ``` 4. The daemon parses the body without checking the caller's identity. 5. The request is written to the MCP subprocess. 6. The operation is forwarded to the authenticated Telegram executor and performed under the victim's account. ### Impact Assessment A reachable attacker can invoke any tool accepted by the MCP subprocess. The resulting s ...[truncated 343 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/http-server.ts:212
Finding

Unbounded HTTP Request Buffering Allows Memory Exhaustion

Content
View full analysis
body += chunk); req.on('end', async () => { ``` The daemon uses the same pattern: ```ts if (req.url === '/call' && req.method === 'POST') { let body = ''; req.on('data', chunk => body += chunk); req.on('end', async () => { ``` ### Technical Analysis Both services append every received chunk to an in-memory string until the client finishes the request. No `Content-Length` limit, streaming parser limit, request timeout, or chunk-count restriction is enforced. A malicious client can send a very large body to consume process memory. Multiple concurrent requests can amplify the effect. A slow client can also keep connections open while gradually transmitting data, consuming sockets and memory. The broad service bindings and missing authentication in the affected servers make this flaw remotely reachable whenever the ports are network-accessible. ### Attack Path 1. The victim starts the HTTP server or daemon. 2. The attacker opens one or more connections to the exposed service. 3. The attacker continuously sends a large POST body to `/mcp` or `/call`. 4. Each chunk is appended to the `body` string. 5. Memory consumption increases until the Node.js process becomes unresponsive, is terminated by the runtime, or is killed by the operating system. 6. Automatic process-restart behavior may cause repeated restart and exhaustion cycles if the attacker continues sending requests. ### Impact Assessment Successful exploitation can disrupt the Telegram MCP bridge and deny legitimate Agent operations. On a resource-constrained host, memory pressure may also degrade unrelated p ...[truncated 81 chars]
Remediation
View remediation
{ received += chunk.length; if (received > MAX_BODY_BYTES) { res.writeHead(413); res.end('Payload Too Large'); req.destroy(); return; } body += chunk.toString('utf8'); }); ``` ]]>

T09 · Insecure Skill Coding Practices

Note
Location
telebiz-service.sh:46
Finding

Service Stop Command Can Terminate Unrelated Processes

Content
View full analysis
/dev/null ``` ### Technical Analysis `pkill -f` matches against the complete command line rather than a verified process identity. Any process whose command line contains `telebiz-mcp` may be terminated, even if it is unrelated to the service instance managed by this script. The script already maintains a PID file and attempts to terminate that PID. The broad fallback therefore exceeds the minimum process privileges necessary for normal service management. ### Attack Path 1. Another user-owned process is started with `telebiz-mcp` somewhere in its command line, argument list, or script path. 2. The user runs `telebiz-service.sh stop` or `telebiz-service.sh restart`. 3. The PID-file-managed process is stopped. 4. `pkill -f "telebiz-mcp"` also matches the unrelated process. 5. The unrelated process receives a termination signal. This is primarily an accidental or locally influenced denial-of-service issue rather than a remote exploitation path. ### Impact Assessment The command may terminate unrelated processes running under the same operating-system user. It generally cannot terminate processes belonging to other users without additional privileges. The impact is loss of availability or interrupted work for matching processes. ]]>
Remediation
View remediation
/cmdline` matches the exact expected executable. 4. Remove stale PID files safely when the recorded process no longer exists. 5. For robust lifecycle management, use a user-level service manager such as systemd with an explicit unit and process identity. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill documentation includes process lifecycle management, PID/log handling, local port checks, pkill-based cleanup, and log following, all of which exceed a normal message-access skill and touch the host operating environment. In a local-agent context, these host-control behaviors are security-relevant because they can disrupt unrelated processes, create persistence, and expand the consequences of misuse beyond Telegram data access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill documentation includes process lifecycle management, PID/log handling, local port checks, pkill-based cleanup, and log following, all of which exceed a normal message-access skill and touch the host operating environment. In a local-agent context, these host-control behaviors are security-relevant because they can disrupt unrelated processes, create persistence, and expand the consequences of misuse beyond Telegram data access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation includes process lifecycle management, PID/log handling, local port checks, pkill-based cleanup, and log following, all of which exceed a normal message-access skill and touch the host operating environment. In a local-agent context, these host-control behaviors are security-relevant because they can disrupt unrelated processes, create persistence, and expand the consequences of misuse beyond Telegram data access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation includes process lifecycle management, PID/log handling, local port checks, pkill-based cleanup, and log following, all of which exceed a normal message-access skill and touch the host operating environment. In a local-agent context, these host-control behaviors are security-relevant because they can disrupt unrelated processes, create persistence, and expand the consequences of misuse beyond Telegram data access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation includes process lifecycle management, PID/log handling, local port checks, pkill-based cleanup, and log following, all of which exceed a normal message-access skill and touch the host operating environment. In a local-agent context, these host-control behaviors are security-relevant because they can disrupt unrelated processes, create persistence, and expand the consequences of misuse beyond Telegram data access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill documentation includes process lifecycle management, PID/log handling, local port checks, pkill-based cleanup, and log following, all of which exceed a normal message-access skill and touch the host operating environment. In a local-agent context, these host-control behaviors are security-relevant because they can disrupt unrelated processes, create persistence, and expand the consequences of misuse beyond Telegram data access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation includes process lifecycle management, PID/log handling, local port checks, pkill-based cleanup, and log following, all of which exceed a normal message-access skill and touch the host operating environment. In a local-agent context, these host-control behaviors are security-relevant because they can disrupt unrelated processes, create persistence, and expand the consequences of misuse beyond Telegram data access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation includes process lifecycle management, PID/log handling, local port checks, pkill-based cleanup, and log following, all of which exceed a normal message-access skill and touch the host operating environment. In a local-agent context, these host-control behaviors are security-relevant because they can disrupt unrelated processes, create persistence, and expand the consequences of misuse beyond Telegram data access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill documentation includes process lifecycle management, PID/log handling, local port checks, pkill-based cleanup, and log following, all of which exceed a normal message-access skill and touch the host operating environment. In a local-agent context, these host-control behaviors are security-relevant because they can disrupt unrelated processes, create persistence, and expand the consequences of misuse beyond Telegram data access.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation includes process lifecycle management, PID/log handling, local port checks, pkill-based cleanup, and log following, all of which exceed a normal message-access skill and touch the host operating environment. In a local-agent context, these host-control behaviors are security-relevant because they can disrupt unrelated processes, create persistence, and expand the consequences of misuse beyond Telegram data access.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 292)May include surrounding context.

md
pkill -f "relay.js"

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The server sets Access-Control-Allow-Origin: * and exposes an authenticated Telegram MCP interface over HTTP with no authentication or origin restrictions. Any website visited by the local user can issue cross-origin requests to http://localhost:9718/mcp and drive Telegram actions through the existing authenticated session, enabling message sending, data access, and account manipulation.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · dist/mcp-server.js (reported line 18)May include surrounding context.

js
ol/sdk/server/index.js';
import { StdioServerTransport } from '@modelcontextprotocol/sdk/server/stdio.js';
import { CallToolRequestSchema, ListToolsRequestSchema, } from '@modelcontextprotocol/sdk/types.js';
import WebSocket from 'ws';
const RELAY_URL = process.env.TELEBIZ_RELAY_URL || 'ws://localhost:9716';
const RECONNECT_INTERVAL = 5000;
// Tool definitions (matching telebiz-tt registry)
const TOOLS = [
    // Chat Tools
    {
        name: 'listChats',
        description: 'Get a list of chats with optional filters. Returns chat IDs, titles, types, and last message info.',
        inputSchema: {
            type: 'object',
            properties: {
                chatType: {
                    type: 'string',
                    enum: ['private', 'group', 'supergroup', 'channel', 'all'],
                    description: 'Filter by chat type. Default: all',
                },
                hasUnread: {
                    type: 'boolean',
                    description: 'true =

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This tool enables outbound messaging from an authenticated Telegram session, which can be used to exfiltrate sensitive data obtained through other tools to arbitrary chats or users. In an agent environment, combining read access with send capability creates a direct data-theft channel and also allows impersonation, spam, or social-engineering from the user's account.

Content

Scanner excerpt · dist/mcp-server.js (reported line 213)May include surrounding context.

js
properties: {
                chatId: {
                    type: 'string',
                    description: 'The ID of the chat to send the message to',
                },
                username: {
                    type: 'string',

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

The forwardMessages tool can transfer existing messages from one chat to another, which is a direct mechanism for unauthorized disclosure of private or confidential conversations. Because it operates within an authenticated account, an agent could silently relay sensitive content across trust boundaries with little friction.

Content

Scanner excerpt · dist/mcp-server.js (reported line 243)May include surrounding context.

js
},
                toChatId: {
                    type: 'string',
                    description: 'The ID of the chat to forward messages to',
                },
                messageIds: {
                    type: 'array',

Known Vulnerable Dependency: @hono/node-server==1.19.9 — 3 advisory(ies): CVE-2026-39406 (@hono/node-server: Middleware bypass via repeated slashes in serveStatic); GHSA-frvp-7c67-39w9 (Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encode); CVE-2026-29087 (@hono/node-server has authorization bypass for protected static paths via encode)

High
Category
Supply Chain
Confidence
93% confidence
Finding

The lockfile pins @hono/node-server 1.19.9, and the reported advisories describe path traversal and authorization/static-file bypass issues in the server adapter. Even though this package is transitive, shipping a known-vulnerable server component is a real supply-chain risk if the MCP SDK exposes HTTP endpoints or static content in this skill’s deployment path.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @modelcontextprotocol/sdk==1.25.3 — 1 advisory(ies): CVE-2026-25536 (@modelcontextprotocol/sdk has cross-client data leak via shared server/transport)

High
Category
Supply Chain
Confidence
96% confidence
Finding

The skill directly depends on @modelcontextprotocol/sdk 1.25.3, which is flagged for a cross-client data leak via shared server/transport. In a Telegram-access skill handling authenticated session data, cross-client leakage could expose chats, messages, or other sensitive account data between different users or sessions.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
86% confidence
Finding

fast-uri 3.1.0 has multiple host-confusion and SSRF-related advisories, making it a meaningful risk where URL parsing influences outbound connections or trust decisions. In an integration-oriented MCP skill that may bridge browser, websocket, or remote-service traffic, malformed URL handling could become security-relevant even if the vulnerable package is transitive.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: hono==4.11.7 — 16 advisory(ies): CVE-2026-56762 (Hono missing validation of cookie name on write path in setCookie()); CVE-2026-47676 (Hono: app.mount() strips mount prefix using undecoded path, causing incorrect ro); CVE-2026-47675 (Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie) +13 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

hono 4.11.7 is present as a peer/transitive package and is associated with numerous advisories affecting routing, cookies, and request handling. Because the MCP SDK depends on Hono ecosystem components, weaknesses in routing or header/cookie handling can materially affect any exposed service surface, especially for an authenticated Telegram data broker.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: path-to-regexp==8.3.0 — 2 advisory(ies): CVE-2026-4923 (path-to-regexp vulnerable to Regular Expression Denial of Service via multiple w); CVE-2026-4926 (path-to-regexp vulnerable to Denial of Service via sequential optional groups)

High
Category
Supply Chain
Confidence
83% confidence
Finding

path-to-regexp 8.3.0 is reported vulnerable to ReDoS/DoS via crafted route patterns. While exploitation often depends on route definitions and attacker reachability, this package sits in the routing stack and can impact availability if exposed through HTTP endpoints serving the MCP integration.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
95% confidence
Finding

The skill directly depends on ws 8.19.0, which is flagged for memory disclosure and memory exhaustion issues. Since this skill’s functionality likely relies on websocket communication for MCP and/or Telegram session bridging, vulnerabilities in ws are especially relevant and could lead to data exposure or service disruption under attacker-controlled traffic.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @modelcontextprotocol/sdk==1.25.3 — 1 advisory(ies): CVE-2026-25536 (@modelcontextprotocol/sdk has cross-client data leak via shared server/transport)

High
Category
Supply Chain
Confidence
91% confidence
Finding

The resolved @modelcontextprotocol/sdk version is reported as affected by a cross-client data leak via shared server/transport. In a skill that accesses authenticated Telegram data, such leakage is especially serious because messages, chat metadata, or session-scoped responses could be exposed across clients or tenants if the vulnerable transport/server pattern is used.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
94% confidence
Finding

The resolved ws version is flagged for memory disclosure and memory exhaustion denial-of-service issues. Because this skill appears to rely on WebSocket-based communication for Telegram access, a vulnerable ws library could let an attacker crash the service or potentially expose process memory contents during crafted WebSocket interactions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The /call endpoint accepts unauthenticated POST requests on localhost and forwards them directly to the MCP process, creating a local privilege boundary bypass. Any untrusted local application, browser-assisted localhost request, or malware running as the same user could invoke Telegram actions such as reading chats or sending messages through the user's authenticated session.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The server explicitly sets Access-Control-Allow-Origin: * and exposes the authenticated Telegram MCP interface over HTTP without any authentication or origin restriction. Any website visited by the user can issue browser-based requests to http://localhost:9718/mcp and drive the authenticated Telegram session, enabling message reads, searches, and message sends through the local browser session.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/daemon.js:36

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/http-server.js:30

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/daemon.ts:43

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/http-server.ts:40

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/daemon.js:19

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/daemon.ts:21