skills/joelhooks/joelclaw/telegram/Gen Agent Trust Hub

telegram

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The documentation provides administrative and troubleshooting shell commands for monitoring processes, searching logs, and testing the Telegram API. It also includes an emergency /kill command to stop the system service.- [INDIRECT_PROMPT_INJECTION]: The skill processes data from an external platform (Telegram), which represents a potential injection surface.
  • Ingestion points: User messages and media are received via the Telegram Bot API through the telegram.ts adapter.
  • Boundary markers: Implements a mandatory single-user lockdown where the middleware discards all traffic from non-authorized Telegram user IDs.
  • Capability inventory: Includes file system writes for media downloads and full interaction capabilities with the Telegram Bot API.
  • Sanitization: Inbound content is processed through a structured pipeline, and outbound formatting is validated before transmission.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — telegram