telegram-mini-app
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the official Telegram Web App JavaScript SDK from 'https://telegram.org/js/telegram-web-app.js'. This is a well-known service domain.
- [DATA_EXFILTRATION]: The skill uses 'tg.initDataUnsafe' to access user information. It correctly identifies the lack of server-side validation of this data as a high-severity security risk ('Sharp Edges' section) and advises the developer to implement validation.
- [SAFE]: All external dependencies, such as '@tonconnect/ui-react', are standard packages within the TON blockchain ecosystem used for wallet integration.
- [SAFE]: The skill does not contain any prompt injection, obfuscation, or persistence mechanisms. Its behavior aligns with its stated purpose as a development guide.
Audit Metadata