Back to skill

Security audit

Telegram Mcp Server

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documentation-only helper for using a Telegram MCP server, and its sensitive Telegram account access is clearly disclosed and purpose-aligned.

Install this only if you intend an agent to operate a real Telegram user account through an MCP server. Treat Telegram session strings and API credentials like passwords, confirm which account label is being used before sending messages, and expect any agent with this tool available to be able to read chats and send messages as that account when instructed.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.