telegram-mini-app

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the official Telegram Web App API script and standard libraries for TON blockchain interaction, which are expected for its stated purpose.- [DATA_EXPOSURE]: The skill handles user identity data (user ID, first name) retrieved from the Telegram Web App API. It addresses potential data integrity risks by providing comprehensive server-side validation logic using HMAC-SHA256 to prevent spoofing.- [PROMPT_INJECTION]: The skill provides patterns for processing external data from the Telegram client interface. It mitigates indirect prompt injection risks by instructing developers to verify the authenticity of all external inputs through server-side hash verification before processing or acting upon the data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 10:55 PM
Security Audit — agent-trust-hub — telegram-mini-app