Back to skill

Security audit

Telegram Telethon CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Telegram account automation tool, but it asks for durable account-level access and lacks enough safeguards around sensitive actions and credential storage.

Review this carefully before installing. Use a separate Telegram profile if possible, avoid saving real API credentials in TOOLS.md or shared repositories, protect or remove ~/.tgctl-telethon sessions when finished, and require explicit user confirmation before any send, delete, admin, block, join/leave, profile, or listen operation. The package is also incomplete as submitted because the installer references a missing tgctl script.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/install.sh:28
Finding

Unpinned Telethon Dependency Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: scripts/install.sh:28
Vulnerability Type: Unpinned and automatically upgraded third-party dependency
Risk Level: Medium

Vulnerable Code:

bash
# Install telethon in venv
echo "Installing telethon..."
"$VENV_DIR/bin/pip" install --quiet --upgrade telethon

Technical Analysis

The installer downloads and installs the newest version of telethon available from pip's configured package index. It does not specify an audited version, use a lock file, or verify package hashes.

The --upgrade option further ensures that rerunning the installer may replace a previously reviewed dependency with a newer, behaviorally different release. Installation is therefore non-reproducible and depends on the state and trustworthiness of the package index, package publisher account, network configuration, and all transitive dependencies at execution time.

This is an insecure dependency-management practice rather than evidence that the current Telethon package is malicious. The risk materializes if an upstream release, publisher account, package index, mirror, or transitive dependency is compromised.

Attack Path

  1. An attacker compromises an upstream package publisher, configured package index, mirror, or transitive dependency.
  2. The attacker publishes a malicious release that satisfies the unconstrained telethon dependency.
  3. A user runs scripts/install.sh.
  4. pip downloads and installs the attacker-controlled release because no version or integrity hash is enforced.
  5. Malicious package code executes during package installation or when the Telegram CLI imports the dependency.
  6. The malicious code operates with the privileges of the user running the installer or CLI.

Impact Assessment

Successful exploitation permits code execution as the invoking user. Depending on when the malicious code executes, it may access user-readable files, environment variab ...[truncated 520 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin Telethon to a specific version that has been reviewed and tested.
  • Pin all transitive dependencies through a reproducible lock file.
  • Generate and verify cryptographic hashes for every downloaded distribution.
  • Install with hash enforcement, for example through a reviewed requirements file and pip install --require-hashes -r requirements.txt.
  • Avoid unconditional --upgrade operations in installation scripts.
  • Use a trusted, explicitly configured package index and consider retaining reviewed dependency artifacts internally.
  • Add automated dependency vulnerability and provenance checks to the release process.
  • Document a controlled procedure for reviewing and updating pinned dependencies.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:37
Finding

Setup Instructions Encourage Persistent Plaintext Storage of Telegram API Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:37-42
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Medium

Vulnerable Documentation:

markdown
### Step 4: Save config to TOOLS.md

```markdown
### tgctl-telethon (Telegram CLI)
- Binary: ~/.local/bin/tgctl-telethon
- Env: TELEGRAM_API_ID=${ID} TELEGRAM_API_HASH=${HASH}
- Session: ~/.tgctl-telethon/
text

### Technical Analysis

The setup procedure explicitly tells users to save configuration in `TOOLS.md` and shows the Telegram API ID and API hash as values in that persistent file. If `${ID}` and `${HASH}` are replaced with real values as implied by the instructions, sensitive credentials are stored in plaintext Markdown.

This conflicts with the security statement at `SKILL.md:129`, which claims that credentials are supplied through environment variables and are never stored in code. Naming credentials as environment-variable assignments does not protect them when the literal values are written into a persistent document.

Markdown configuration files may be read by other tools or agents, included in backups, synchronized to remote systems, copied into diagnostic output, or committed to source control. Telegram API credentials do not by themselves constitute a complete authenticated user session, but their disclosure weakens credential security and can facilitate abuse when combined with phone verification, session data, or other authentication material.

### Attack Path

1. A user follows the documented setup process.
2. The user replaces `${ID}` and `${HASH}` with actual Telegram API credential values in `TOOLS.md`.
3. The plaintext file is read by another local process or agent, included in a backup, synchronized, shared, logged, or committed to a repository.
4. An unauthorized party obtains the API ID and API hash.
5. The exposed values are used in attempts to impersonate the registered Telegram application or are
...[truncated 795 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not instruct users to place literal API IDs or API hashes in TOOLS.md.

  • Show only variable names or redacted placeholders in persistent documentation, for example:

    markdown
    - Required environment variables: `TELEGRAM_API_ID`, `TELEGRAM_API_HASH`
    - Credential source: OS keychain or approved secret manager
    
  • Store sensitive values in an operating-system keychain, credential manager, or another access-controlled secret store.

  • If a local environment file must be supported, require restrictive permissions such as mode 0600, exclude it from source control, and clearly document the residual plaintext-storage risk.

  • Add relevant secret files and local configuration files to .gitignore.

  • Warn users not to include credentials in repositories, logs, prompts, chat messages, backups, or shared documentation.

  • Provide credential rotation guidance for users who may already have followed the existing instructions.

  • Update the security claims so they accurately reflect the implemented credential-handling process.

Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes shell-based installation and runtime commands but does not declare any tool scope or allowed-tools constraints. That omission can let an agent use shell access more broadly than intended, increasing the chance of unauthorized command execution, package installation, or filesystem changes when the skill is activated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The skill explicitly persists Telegram user sessions under ~/.tgctl-telethon//, creating durable authenticated access to a personal account. If the host, profile directory, or downstream tooling is compromised, attackers could reuse the session to read messages, impersonate the user, or perform Telegram actions without reauthentication.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: telegram-telethon
description: Manage Telegram via tgctl-telethon CLI (Python/Telethon) - send/forward/edit/delete/pin messages, search, list chats/members, join/leave groups, kick/invite users, block/unblock, send files, download media, start bots, create groups/channels, manage admins, update profile, listen for messages. Use when user asks to interact with Telegram as a user account (not bot API). Powered by Telethon (MTProto).
---

# Telegram CLI (tgctl-telethon)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation text says to use the skill whenever a user asks to interact with Telegram, which is a broad trigger for a highly privileged user-account automation tool. Overbroad routing can cause the agent to invoke Telegram actions in ambiguous situations and perform messaging, account, or group operations without sufficiently specific user intent checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises destructive and privacy-impacting capabilities such as delete, kick, block, invite, manage admins, listen for messages, and profile changes without front-loaded warnings about consent, irreversibility, or surveillance implications. In a user-account Telegram context, these actions can affect real conversations, memberships, and account reputation, making accidental or coerced use materially harmful.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This shell script creates a virtual environment under $HOME and writes a wrapper executable to $HOME/.local/bin. Although it prints progress messages, it does not clearly disclose up front that it will modify the user's filesystem and install a runnable command in PATH-managed locations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.