T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:82- Finding
Excessive Telegram Bot Permissions and Message Visibility
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:82,SKILL.md:96, andSKILL.md:144-154
Vulnerability Type: Excessive bot privileges and unnecessary access to group messages
Risk Level: MediumRelevant excerpts:
markdown - [ ] Bot 是管理员(能收消息)markdown 3. **设为管理员**(才能收消息)markdown ### Q: 收不到消息? - Bot 是管理员吗? - 频道 ID 在 allowed_chats 里吗? ### Q: 艾特没反应? - 对方 Bot 在这个群吗? - **privacy mode 关了吗?** - 找 @BotFather - 发送 /mybots - 选你的 Bot - Bot Settings → Group Privacy → Turn offTechnical Analysis
The Skill broadly directs users to grant a Telegram bot administrator status and disable Telegram group privacy mode. Administrator status may grant moderation capabilities beyond those required for mention-based communication. Disabling privacy mode can also allow the bot to receive group messages that are not explicitly addressed to it.
The instructions do not identify which individual administrator permissions are necessary, explain the expanded message visibility, or distinguish optional full-message processing from the minimum configuration needed for mention-based interaction. This violates least-privilege principles.
The
allowed_chatsconfiguration limits which chats OpenClaw should process, but it does not eliminate the risks created by excessive Telegram-side permissions or a compromised bot token.Attack Path
- A user follows the Skill and adds an OpenClaw-controlled bot to a Telegram group.
- The user grants the bot administrator status without restricting its individual administrative capabilities.
- The user disables group privacy mode as instructed.
- The bot gains visibility into messages beyond direct commands or explicit mentions and may receive moderation capabilities.
- An attacker who compromises the bot implementation, host, or bot token can use this access to collect group messages or abuse any granted administrative func ...[truncated 739 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not require administrator status by default. State that ordinary group membership should be used whenever it supports the intended mention-based workflow.
- Document the exact Telegram permission required for every feature. If administration is unavoidable, instruct users to enable only the specific capability needed and disable all unrelated moderation rights.
- Keep Telegram group privacy mode enabled for workflows that only need commands, replies, or explicit mentions.
- Treat disabling privacy mode as an optional high-visibility configuration and display a clear warning that the bot may receive unrelated group messages.
- Use a dedicated test group before enabling the bot in a production or sensitive community.
- Restrict
allowed_chatsto explicitly approved chat IDs and verify that the bot rejects messages from all other chats. - Protect the Telegram bot token using an appropriate secret store, avoid committing it to source control, and rotate it immediately after suspected compromise.
- Periodically review the bot's group membership, administrator rights, message visibility, and authorized chat list.
- Update troubleshooting guidance so it does not present administrator access or disabled privacy mode as universal fixes.
