Back to skill

Security audit

Telegram Channel Reader

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate Telegram channel reader, but it needs Review because its login flow and stored session can expose sensitive Telegram account data if used carelessly.

Install only if you are comfortable granting this skill access to a Telegram account session that can read private channels available to that account. Prefer self-authentication or stdin over /tmp code/password files, avoid using the Telethon auth output in logged environments, keep session and backup files private, and install in a dedicated virtual environment with reviewed dependency versions where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
reader.py:702
Finding

Predictable Shared Temporary Files Are Used for Telegram Login Secrets

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
reader_telethon.py:625
Finding

Telethon Authentication Logs the Account Phone Number

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
setup.py:15
Finding

Security-Sensitive Dependencies Are Installed Without Exact Version or Hash Pinning

Content
View full analysis
=2.3.69", "tgcrypto>=1.2.0", "telethon>=1.24.0", ], ``` The documentation additionally recommends resolving the latest available releases: ```bash pip install pyrofork tgcrypto telethon pip install -e . ``` ### Technical Analysis The package specifies only lower version bounds and provides no lock file or package hashes. Installation can therefore select any future release satisfying the constraints. These dependencies run in the same Python process as the Skill and receive highly sensitive values or access: - `TG_API_ID` and `TG_API_HASH`. - SOCKS proxy credentials, if configured. - Telegram login codes and cloud 2FA passwords during authentication. - The reusable Telegram session database. - Content from private channels available to the authenticated account. `pyrofork` is a community-maintained replacement that installs into the `pyrogram` import namespace. This is intentional and documented, but it makes dependency provenance particularly security-sensitive. A compromised package-index account, malicious future release, dependency takeover, or unsafe mirror could introduce code that executes with all privileges of the user running the Skill. No evidence was found that the currently declared package names are typosquatted or malicious. The vulnerability is the absence of reproducible, integrity-verified dependency resolution. ### Attack Path 1. An attacker compromises a dependency maintainer account, package-index delivery path, or configured package mirror, or publishes a malicious future version through another supply-chain failure. 2. The malicious version still satisfies the broad `>=` requirement. 3. A user follows the docum ...[truncated 1253 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (28)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 54)May include surrounding context.

led, uninstall it first — they share a namespace. pip uninstall pyrogram -y 2>/dev/null pip install pyrofork tgcrypto telethon pip install -e .

text

> **Linux users:** if you get `externally-managed-environment` error, use a virtual environment:
> ```bash
> python3 -m venv ~/.venv/tg-reader
> ~/.venv/tg-reader/bin/pip install pyrofork tgcrypto telethon
> ~/.venv/tg-reader/bin/pip install -e .
> echo 'export PATH="$HOME/.venv/tg-reader/bin:$PATH"' >> ~/.bashrc
> source ~/.bashrc
> ```

## Manual Install

```bash
cd ~/.openclaw/workspace/skills
git clone https://github.com/bzSega/sergei-mikhailov-tg-channel-reader
cd sergei-mikhailov-tg-channel-reader
pip install pyrofork tgcrypto telethon
pip install -e .

Setup

Step 1 — Get Telegram API credentials

You need a personal Telegram API key. This is free and takes 2 minutes.

  1. Open https://my.telegram.org in your browser
  2. Enter your phone number (with country code, e.g. +79991234567) and click Send Code
  3. Enter th

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 593)May include surrounding context.

workspace/skills/sergei-mikhailov-tg-channel-reader bash setup-tg-reader.sh

text

The setup script: installs Python packages (`pip install .`), checks credentials and session, runs `tg-reader-check`, and prints the exec approval commands for you to run manually.

On Linux with managed Python (Ubuntu/Debian), use a venv **before** running the setup script:

```bash
python3 -m venv ~/.venv/tg-reader
echo 'export PATH="$HOME/.venv/tg-reader/bin:$PATH"' >> ~/.bashrc && source ~/.bashrc
Manual install (without setup script)
bash
cd ~/.openclaw/workspace/skills/sergei-mikhailov-tg-channel-reader
# pyrofork replaces pyrogram; uninstall pyrogram first if it was already installed
pip uninstall pyrogram -y 2>/dev/null
pip install pyrofork tgcrypto telethon && pip install .
openclaw approvals allowlist add --gateway "$(which tg-reader)"
openclaw approvals allowlist add --gateway "$(which tg-reader-check)"

Step 4 — Authenticate

bash
tg

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The changelog advertises a setup script that automatically adds commands to an exec approval allowlist, which weakens an explicit security control by pre-approving future command execution. In an agent-driven environment, silently normalizing or encouraging automatic allowlisting can increase the blast radius of prompt injection or command abuse, especially if users do not clearly understand what is being trusted.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CHANGELOG.md (reported line 276)May include surrounding context.

md
## [0.8.7] - 2026-03-01

**Write output to a file instead of flooding the agent's context.** New `--output` flag saves fetch results (especially large comment payloads) to a file. The agent gets a short confirmation on stdout instead of the full JSON — saving tokens. Works great with cron: schedule periodic updates to a file, then analyze on demand without re-fetching.

### Added
- `--output` flag for `fetch` command — writes results to a file instead of stdout

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · CHANGELOG.md (reported line 482)May include surrounding context.

md
### Security
- `test_session.py`: replaced partial `api_hash[:10]` print with masked output (`***`) to prevent secret leakage in logs or shared terminals
- `SKILL.md`: added `chmod 600` step after auth to restrict session file permissions

---

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The README instructs users to install via npx clawhub@latest, which pulls and executes the latest published package without pinning a specific version. If the upstream package or dependency chain is compromised, users may run unexpected code during installation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 82)May include surrounding context.

md
- **App title**: any name (e.g. `MyReader`)
   - **Short name**: any short word (e.g. `myreader`)
   - Other fields can be left as default
6. Click **"Create application"**
7. You'll see your credentials:
   - **App api_id** — a number like `12345678`
   - **App api_hash** — a 32-character string like `a1b2c3d4e5f6789012345678abcdef12`

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 101)May include surrounding context.

"api_hash": "your_api_hash_here" } EOF chmod 600 ~/.tg-reader.json

text
Works everywhere — agents, servers, interactive shells. File is outside the project and never committed.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 567)May include surrounding context.

"api_hash": "your_api_hash_here" } EOF chmod 600 ~/.tg-reader.json

text
Works everywhere — agents, servers, interactive shells. File is outside the project and never committed.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The suggested trigger phrases such as "check", "read", or "monitor" a Telegram channel are broad and overlap with normal user language. In agentic systems, this can cause unintended activation of the skill in contexts where the user did not explicitly consent to using Telegram account-backed tooling.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
# Human-readable output
tg-reader fetch @channel_name --since 24h --format text

# Write output to file instead of stdout (saves tokens)
tg-reader fetch @channel_name --since 24h --output
tg-reader fetch @channel_name --since 24h --comments --output comments.json

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill explicitly directs users to store long-lived Telegram API credentials in ~/.tg-reader.json. Although presented as setup guidance, this creates persistent local secret storage tied to a tool that also manages full-account session files, increasing the impact of host compromise or accidental file disclosure.

Content

Scanner excerpt · SKILL.md (reported line 555)May include surrounding context.

md
### Step 1 — Get API Credentials

Go to https://my.telegram.org → **API Development Tools** → create an app → copy `api_id` and `api_hash`.

### Step 2 — Save Credentials

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill instructs users to install via npx clawhub@latest, which fetches and executes the latest remote package without pinning a version or integrity hash. If the upstream package is compromised or a breaking release is published, users may execute unreviewed code during installation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises itself as a channel reader but includes substantially broader capabilities: full Telegram account authorization, session backup/restore, and lifecycle management. This scope expansion increases the trust required from the user and creates a larger attack surface around account access and credential handling than a simple reader would need.

Content

No source excerpt is available for this finding.

Tainted flow: 'progress' from os.environ.get (line 693, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
86% confidence
Finding

The code writes auth-progress data to a file path taken directly from the TG_AUTH_PROGRESS environment variable without validation. In environments where untrusted callers can influence environment variables, this enables arbitrary file append/write as the running user, which can overwrite logs, poison state files, or target sensitive paths via symlinks.

Content

Scanner excerpt · reader.py (reported line 696)May include surrounding context.

python
progress = os.environ.get("TG_AUTH_PROGRESS")
    if progress:
        try:
            with open(progress, "a") as f:
                f.write(line + "\n")
        except OSError:
            pass

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The code persists phone numbers and manages long-lived authentication state, which is sensitive account metadata beyond the minimum required to merely fetch channel content. In an agent setting with unclear purpose boundaries, retaining such data increases privacy risk and the consequences of filesystem compromise or misuse by other local components.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This section actively initiates Telegram login by sending codes, accepting login codes and 2FA passwords, and installing new sessions. That is a materially stronger capability than reading public/private channels and, if invoked by an untrusted or over-permissioned agent workflow, could enroll or switch Telegram accounts without sufficiently clear separation of duties.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reader.py (reported line 1036)May include surrounding context.

python
def _write_output(result, output_path, fmt, since_label):
    """Write output to a file and print a short confirmation to stdout."""
    output_path = os.path.abspath(output_path)
    with open(output_path, "w", encoding="utf-8") as f:
        if fmt == "json":

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reader.py (reported line 155)May include surrounding context.

python
"error": f"Session file not found: {session_file}",
        "expected_path": str(session_file),
        "fix": [
            "Run 'tg-reader-telethon auth' to create a new session",
            "Or set TG_SESSION=/path/to/existing-session (without .session suffix)",
            "Or add {\"session\": \"/path/to/session\"} to ~/.tg-reader.json",
            "Or pass --session-file /path/to/session (without .session suffix)",

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reader_telethon.py (reported line 145)May include surrounding context.

python
"error": f"Session file not found: {session_file}",
        "expected_path": str(session_file),
        "fix": [
            "Run 'tg-reader-telethon auth' to create a new session",
            "Or set TG_SESSION=/path/to/existing-session (without .session suffix)",
            "Or add {\"session\": \"/path/to/session\"} to ~/.tg-reader.json",
            "Or pass --session-file /path/to/session (without .session suffix)",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The interactive auth flow prints sensitive account identifiers, including the user's phone number and account identity, directly to stdout and in JSON output. In agent, CI, terminal-logging, or orchestrated environments, stdout is often captured, persisted, or forwarded, which can expose personal data beyond the immediate user.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · tg_check.py (reported line 300)May include surrounding context.

python
for name in ("pyrogram", "telethon", "tgcrypto"):
        try:
            mod = __import__(name)
            version = getattr(mod, "__version__", "unknown")
            result[name] = {"installed": True, "version": version}
        except ImportError:

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · tg_check.py (reported line 407)May include surrounding context.

python
"""Online check: does the resolved session hold an authorized user?

    Runs only when the session file exists — connecting with a missing file
    would CREATE a fresh unauthorized session file as a side effect. Takes the
    session lock (short timeout) so it never races a running fetch.

    Returns:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The text instructs the agent to reassure the user that the session never leaves the machine, which is persuasive language that can bias the user's risk assessment rather than neutrally presenting facts. In security-sensitive auth flows, agent instructions that push reassurance can reduce informed consent and make users less likely to scrutinize storage, access, or backup behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The cron setup instructions say to include the exact 'tg-reader' command in the task description, but they do not define how narrowly the reminder should be phrased or what descriptions should not trigger the skill. In a manifest-like instruction context, this can create ambiguity about when the agent should invoke the skill from scheduled reminders.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.