telegram-mini-app

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the official Telegram Web App JavaScript SDK from 'https://telegram.org/js/telegram-web-app.js'. This is a well-known service domain.
  • [DATA_EXFILTRATION]: The skill uses 'tg.initDataUnsafe' to access user information. It correctly identifies the lack of server-side validation of this data as a high-severity security risk ('Sharp Edges' section) and advises the developer to implement validation.
  • [SAFE]: All external dependencies, such as '@tonconnect/ui-react', are standard packages within the TON blockchain ecosystem used for wallet integration.
  • [SAFE]: The skill does not contain any prompt injection, obfuscation, or persistence mechanisms. Its behavior aligns with its stated purpose as a development guide.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — telegram-mini-app