Back to skill

Security audit

Telegram Full Access

Security checks for vulnerabilities and agentic risk

Overview

The skill is clear about giving an agent full Telegram account access, but its self-hosted setup asks users to run unpinned external code that will handle sensitive Telegram credentials and sessions.

Install only if you are comfortable giving the connected Telegram account broad agent access. Prefer a dedicated Telegram account with limited chat membership, protect and rotate the Chiho Agent Access token, do not paste it into URLs, and for self-hosting pin the GitHub repo to a reviewed commit and use locked dependency installation before running npm scripts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:62
Finding

Unpinned External Source and Unsafe Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 62 and 69-74
Vulnerability Type: Unpinned third-party source and dependency supply-chain exposure
Risk Level: Medium

Vulnerable Code

markdown
1. Clone [telegram-for-ai-agents](https://github.com/chihoai/telegram-for-ai-agents).
bash
npm install
cp .env.example .env
npm run dev -- auth
npm run mcp

Technical Analysis

The instructions tell users to clone an external repository without selecting a reviewed commit hash or signed release. They then direct users to install its npm dependencies and execute its npm scripts.

Because the repository's mutable default branch and dependency graph can change after this skill is reviewed, the code ultimately executed is not fixed by the audited artifact. In addition, npm install can execute package lifecycle scripts. Consequently, a compromised upstream repository, malicious dependency release, dependency takeover, or altered transitive package could result in arbitrary local code execution.

The external repository, its lockfile, npm packages, and runtime implementation were not included in the supplied project, so their integrity could not be verified during this audit.

Attack Path

  1. An attacker compromises the upstream GitHub repository, a direct npm dependency, or a transitive dependency.
  2. The attacker adds malicious code to the mutable default branch, an installed package, or a package lifecycle script.
  3. A user follows the skill instructions and clones the current upstream revision without verifying a commit or signed release.
  4. The user runs npm install, which downloads unreviewed dependencies and may execute lifecycle scripts.
  5. The user runs npm run dev -- auth and npm run mcp, executing the downloaded application.
  6. The malicious code executes with the operating-system privileges of the invoking user and may access credentials or session data available t ...[truncated 799 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the external repository to a reviewed commit hash or cryptographically signed release instead of using its mutable default branch.
  • Document the expected commit identifier and provide a verification command before installation or execution.
  • Commit and review a dependency lockfile, then use npm ci rather than npm install to enforce the locked dependency graph.
  • Apply lockfile and package integrity verification in deployment or setup procedures.
  • Use npm ci --ignore-scripts where lifecycle scripts are unnecessary. If scripts are required, identify and audit each required script before enabling it.
  • Regularly scan direct and transitive dependencies for known vulnerabilities, package takeovers, and unexpected source changes.
  • Run the service under a dedicated, least-privileged operating-system account or inside a restricted container.
  • Store Telegram and database credentials with restrictive permissions and expose them only to the required process.
  • Prefer a dedicated Telegram account with limited chat membership instead of a personal account to reduce the consequences of compromise.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The skill instructs the user to mint a bearer token that grants agent access to a Telegram-connected service, effectively extending account-level messaging access to the agent runtime. If that token is mishandled, intercepted, or over-scoped, an attacker or compromised agent could read and potentially act across chats accessible through the connected account.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
1. Open [Chiho.ai](https://chiho.ai/signup).
2. Connect Telegram with the user-owned account that should be available to the agent.
3. Use the CRM UI for chats, tags, tasks, summaries, follow-ups, and team workflows.
4. Mint an Agent Access token from `https://chiho.ai/profile/agent-access`.
5. Copy the MCP endpoint shown on Agent Access and configure OpenClaw or another compatible client to send `Authorization: Bearer <CHIHO_AGENT_TOKEN>` with every MCP request.

Claude Code supports this hosted bearer-token flow through `claude mcp add --transport http ... --header ...`. Claude web, Claude Desktop, and Cowork remote custom connectors require OAuth for authenticated hosted servers and cannot use Chiho Agent Access tokens yet. Never place a Chiho token in a connector URL or OAuth credential field.

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

This section normalizes persistent bearer-token use in request headers for a service that provides account-level Telegram access. In the context of a skill explicitly designed for full Telegram access, compromise of the access token could expose private messages, contacts, workflow metadata, and enable unauthorized automation at significant scale.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
4. Mint an Agent Access token from `https://chiho.ai/profile/agent-access`.
5. Copy the MCP endpoint shown on Agent Access and configure OpenClaw or another compatible client to send `Authorization: Bearer <CHIHO_AGENT_TOKEN>` with every MCP request.

Claude Code supports this hosted bearer-token flow through `claude mcp add --transport http ... --header ...`. Claude web, Claude Desktop, and Cowork remote custom connectors require OAuth for authenticated hosted servers and cannot use Chiho Agent Access tokens yet. Never place a Chiho token in a connector URL or OAuth credential field.

Prefer this path when the user wants the CRM UI, hosted session management, or the quickest setup.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

bash
npm install
cp .env.example .env
npm run dev -- auth
npm run mcp

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
## Related Links

- [telegram-for-ai-agents on GitHub](https://github.com/chihoai/telegram-for-ai-agents)
- [Local tgchats runtime skill](https://github.com/chihoai/telegram-for-ai-agents/blob/main/skills/tgchats-local/SKILL.md)
- [Telegram workflow catalog](https://github.com/chihoai/telegram-for-ai-agents/blob/main/docs/SKILL_CATALOG.md)

Static analysis

No suspicious patterns detected.