Back to skill

Security audit

Openclaw Telegram Chat

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Telegram setup skill, but it asks users to grant broad bot access and handle sensitive identifiers without enough safety guidance.

Review carefully before installing or following the guide. Use a dedicated Telegram bot and token, keep the token out of shared files and repositories, restrict allowed_chats, avoid administrator status unless truly required, grant only minimal Telegram permissions, keep privacy mode enabled where possible, and make sure group participants understand what the bot can see.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:82
Finding

Excessive Telegram Bot Permissions and Message Visibility

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:82, SKILL.md:96, and SKILL.md:144-154
Vulnerability Type: Excessive bot privileges and unnecessary access to group messages
Risk Level: Medium

Relevant excerpts:

markdown
- [ ] Bot 是管理员(能收消息)
markdown
3. **设为管理员**(才能收消息)
markdown
### Q: 收不到消息?

- Bot 是管理员吗?
- 频道 ID 在 allowed_chats 里吗?

### Q: 艾特没反应?

- 对方 Bot 在这个群吗?
- **privacy mode 关了吗?** 
  - 找 @BotFather
  - 发送 /mybots
  - 选你的 Bot
  - Bot Settings → Group Privacy → Turn off

Technical Analysis

The Skill broadly directs users to grant a Telegram bot administrator status and disable Telegram group privacy mode. Administrator status may grant moderation capabilities beyond those required for mention-based communication. Disabling privacy mode can also allow the bot to receive group messages that are not explicitly addressed to it.

The instructions do not identify which individual administrator permissions are necessary, explain the expanded message visibility, or distinguish optional full-message processing from the minimum configuration needed for mention-based interaction. This violates least-privilege principles.

The allowed_chats configuration limits which chats OpenClaw should process, but it does not eliminate the risks created by excessive Telegram-side permissions or a compromised bot token.

Attack Path

  1. A user follows the Skill and adds an OpenClaw-controlled bot to a Telegram group.
  2. The user grants the bot administrator status without restricting its individual administrative capabilities.
  3. The user disables group privacy mode as instructed.
  4. The bot gains visibility into messages beyond direct commands or explicit mentions and may receive moderation capabilities.
  5. An attacker who compromises the bot implementation, host, or bot token can use this access to collect group messages or abuse any granted administrative func ...[truncated 739 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not require administrator status by default. State that ordinary group membership should be used whenever it supports the intended mention-based workflow.
  2. Document the exact Telegram permission required for every feature. If administration is unavoidable, instruct users to enable only the specific capability needed and disable all unrelated moderation rights.
  3. Keep Telegram group privacy mode enabled for workflows that only need commands, replies, or explicit mentions.
  4. Treat disabling privacy mode as an optional high-visibility configuration and display a clear warning that the bot may receive unrelated group messages.
  5. Use a dedicated test group before enabling the bot in a production or sensitive community.
  6. Restrict allowed_chats to explicitly approved chat IDs and verify that the bot rejects messages from all other chats.
  7. Protect the Telegram bot token using an appropriate secret store, avoid committing it to source control, and rotate it immediately after suspected compromise.
  8. Periodically review the bot's group membership, administrator rights, message visibility, and authorized chat list.
  9. Update troubleshooting guidance so it does not present administrator access or disabled privacy mode as universal fixes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The configuration example tells users to place a Telegram bot token directly into a YAML file without warning that the token is a secret credential. If copied into chats, screenshots, repos, or shared config files, the token could let an attacker fully control the bot, impersonate it, or read/send messages depending on integration behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to disclose both a personal handle/name and GitHub ID to an administrator and group without any privacy warning, minimization guidance, or explanation of retention/use. This can enable unnecessary identity linkage, doxxing, or social engineering, especially since the document frames GitHub as an identity credential for community access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to disable Telegram group privacy mode but omits that this increases the bot's visibility into group messages beyond direct mentions/commands. That broader access can capture unrelated participant content and expands the privacy impact of running the bot in shared groups.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing natural-language content exclusively in Chinese for the listed changes. Under the language/locale policy, forcing a specific language without opt-in or justification can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, and there is no indication that the skill is region-specific or that users may choose another language. Under the policy rule for language or locale constraints, forcing a single language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.