tgcloud
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
tgcloud-mcppackage globally and use the@tgcloud/botscaffold. These packages originate from the platform's infrastructure and are necessary for the skill's primary function of managing Telegram serverless bots. - [COMMAND_EXECUTION]: The skill utilizes several CLI commands (e.g.,
push,migrate,run_handler,webhook_sync) to manage the project lifecycle. It incorporates critical guardrails by requiring explicit user confirmation before executing potentially destructive operations such asreset,push force, and non-dry-run migrations. - [INDIRECT_PROMPT_INJECTION]: The skill processes Telegram updates that act as ingestion points for untrusted external data, which could potentially influence agent behavior during testing and debugging cycles.
- Ingestion points: The
run_handlertool accepts arbitrary input in theargsparameter (e.g.,text,chatobjects) meant to simulate Telegram bot updates. - Boundary markers: The instructions do not specify the use of delimiters or warnings to the agent to ignore instructions embedded within the simulated update data.
- Capability inventory: The skill environment provides capabilities for network requests (
fetch), database queries (db), and deployment actions (push,migrate). - Sanitization: There are no explicit instructions for the agent to sanitize or validate the external content before processing it.
- [CREDENTIALS_SAFE]: The skill documentation includes best practices for secret management, specifically instructing that CLI access tokens should only be used with the
login_bottool and never printed, committed to version control, or stored in plain text files. It also correctly advises against committing the.tgcloud/directory, which contains sensitive credentials and cache.
Audit Metadata