Back to skill

Security audit

telegram-checklist

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Telegram checklist tool that uses a user Telethon session, with meaningful allowlist controls and no evidence of hidden or destructive behavior.

Install only if you are comfortable giving this skill access to a Telethon user session that can read and modify native checklists in Saved Messages and explicitly allowlisted Telegram groups/topics. Keep TELETHON_CHECKLIST_CHATS narrow, protect the session file, and do not put secrets or personal data into checklist items.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The public description understates the actual behavior: beyond create/append/toggle, the skill can read checklist state, enumerate topics, consume Telegram API credentials, and process plan files. This mismatch can mislead operators into granting or invoking the skill with less scrutiny than a credentialed write-capable Telethon client deserves, enabling unauthorized or unexpected data access/actions.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · telethon_checklist.py (reported line 37)May include surrounding context.

python
state under "verified"; non-fatal issues are reported under "warnings".

Requires a configured Telethon user session:
    TELETHON_API_ID, TELETHON_API_HASH   in ~/.hermes/.env (from my.telegram.org)
    session file                         ~/.hermes/telethon/<name>.session
    TELETHON_CHECKLIST_CHATS=-100...     allowed chats/topics (comma-separated), optional
    TELETHON_SESSION                     override the session file path, optional

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · telethon_checklist.py (reported line 90)May include surrounding context.

python
state under "verified"; non-fatal issues are reported under "warnings".

Requires a configured Telethon user session:
    TELETHON_API_ID, TELETHON_API_HASH   in ~/.hermes/.env (from my.telegram.org)
    session file                         ~/.hermes/telethon/<name>.session
    TELETHON_CHECKLIST_CHATS=-100...     allowed chats/topics (comma-separated), optional
    TELETHON_SESSION                     override the session file path, optional

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · telethon_checklist.py (reported line 135)May include surrounding context.

python
state under "verified"; non-fatal issues are reported under "warnings".

Requires a configured Telethon user session:
    TELETHON_API_ID, TELETHON_API_HASH   in ~/.hermes/.env (from my.telegram.org)
    session file                         ~/.hermes/telethon/<name>.session
    TELETHON_CHECKLIST_CHATS=-100...     allowed chats/topics (comma-separated), optional
    TELETHON_SESSION                     override the session file path, optional

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · telethon_checklist.py (reported line 153)May include surrounding context.

python
state under "verified"; non-fatal issues are reported under "warnings".

Requires a configured Telethon user session:
    TELETHON_API_ID, TELETHON_API_HASH   in ~/.hermes/.env (from my.telegram.org)
    session file                         ~/.hermes/telethon/<name>.session
    TELETHON_CHECKLIST_CHATS=-100...     allowed chats/topics (comma-separated), optional
    TELETHON_SESSION                     override the session file path, optional

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · telethon_checklist.py (reported line 207)May include surrounding context.

python
state under "verified"; non-fatal issues are reported under "warnings".

Requires a configured Telethon user session:
    TELETHON_API_ID, TELETHON_API_HASH   in ~/.hermes/.env (from my.telegram.org)
    session file                         ~/.hermes/telethon/<name>.session
    TELETHON_CHECKLIST_CHATS=-100...     allowed chats/topics (comma-separated), optional
    TELETHON_SESSION                     override the session file path, optional

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · telethon_checklist.py (reported line 145)May include surrounding context.

python
if v is None or (v == "" and not empty_wins):
        if HERMES is None:
            return None
        return _load_env_file(HERMES / ".env").get(name)
    return v

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill uses sensitive capabilities (environment variables, local file access, and shell execution) but does not declare an explicit tool scope or permissions boundary. That creates a governance gap: an agent runtime may expose more capability than users or policy expect, increasing the chance of unintended credential access or command execution under the guise of a narrow Telegram checklist skill.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
79% confidence
Finding

The skill depends on a persistent Telethon user session stored on disk and API credentials from the environment. Persistent authenticated sessions are sensitive artifacts; if the host, session file, or adjacent tooling is compromised, an attacker could act as the Telegram user within the allowlisted scope without re-authentication.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
---
# Telegram Checklist (native To-Do lists via Telethon)

Create and maintain native Telegram checklist objects (checkboxes, progress counter, shared completion) from a Telethon user session. The Bot API `sendChecklist` works only on behalf of a business account into its private chats with customers - a bot cannot post a checklist into a group or forum topic. MTProto under a user session can, which is what this skill does. Creating a checklist requires Telegram Premium on the acting account; reading or completing one does not. Keep this skill separate from any read-only Telethon reader.

## Requirements (one-time)
- a configured Telethon user session: `TELETHON_API_ID` / `TELETHON_API_HASH` in `~/.hermes/.env` (from my.telegram.org), session file in `~/.hermes/telethon/` (default `user.session`; override with `TELETHON_SESSION`)

Session Persistence

Medium
Category
Rogue Agent
Confidence
72% confidence
Finding

The module intentionally operates using a persistent Telegram user session, which means possession of the session file can grant ongoing account access without re-entering credentials. In an agent context, this materially increases blast radius: compromise of the host, workspace, or session path may let an attacker read or act as the Telegram user within the tool's allowed scope.

Content

Scanner excerpt · telethon_checklist.py (reported line 4)May include surrounding context.

python
#!/usr/bin/env python3
"""telethon_checklist.py - native Telegram To-Do lists (checklists) via Telethon.

WRITE module for a Hermes agent: create / read / append / toggle native Telegram
To-Do lists (checkboxes, progress, shared completion) from a user session. The
Bot API cannot post these into groups or forum topics (sendChecklist works only
on behalf of a business account, into private chats); MTProto under a user

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · telethon_checklist.py (reported line 170)May include surrounding context.

python
Comma-separated entries: '-100123' (whole chat) or '-100123:33' (topic 33
    only). Only negative chat ids (groups/channels) are accepted - user peers
    stay out of scope for a WRITE tool. Topic ids start at 2: the General
    topic (1) cannot be topic-restricted, allow the whole chat instead.
    Saved Messages ('me') is always allowed. Bad entries produce a warning
    that never echoes the raw value (it could be a mispasted secret).

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · telethon_checklist.py (reported line 344)May include surrounding context.

python
def _lock_session():
    """Best-effort chmod 0600 on the ACTUAL session file. Telethon decides the
    filename by STRING suffix (str.endswith('.session')), not pathlib .suffix -
    so a file literally named '.session' is used as-is, not doubled. chmod only
    a regular file (never a directory) and never let this raise."""

Static analysis

No suspicious patterns detected.