telegram-bot-security-analysis skill
Reverse engineer and security-test Telegram bots — API analysis, callback interception, exploit discovery, and vulnerability documentation
Is the telegram-bot-security-analysis skill safe?
Clean: nothing in its files matched our rules. We read 5 files in the folder on 2026-09-28.
No findings.
Install the telegram-bot-security-analysis skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/kevinnft/ai-agent-skills.git /tmp/ai-agent-skills mkdir -p ~/.claude/skills cp -r /tmp/ai-agent-skills/skills/research/telegram-bot-security-analysis ~/.claude/skills/telegram-bot-security-analysis
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Telegram Bot Security Analysis
Comprehensive methodology for analyzing Telegram bots to discover security vulnerabilities, reverse engineer backend systems, and document exploits.
Core Workflow
1. Initial Reconnaissance
Login and Access:
from telethon import TelegramClient
API_ID = 94575 # Public Telegram API credentials
API_HASH = 'a3406de8d171bb422bb6ddf3bbd800e2'
client = TelegramClient('session_name', API_ID, API_HASH)
await client.start()Bot Information Gathering:
- Bot ID and access hash
- Available commands
- Button callback data
- Web app URLs
- Inline query support
Command Discovery:
commands = [
'/help', '/menu', '/balance', '/wallet', '/deposit',
'/withdraw', '/profile', '/settings', '/admin', '/debug'
]
for cmd in commands:
await client.send_message(bot, cmd)
await asyncio.sleep(1)Conversation Dump:
all_msgs = await client.get_messages(bot, limit=200)
conversation = []
for msg in reversed(all_msgs):
if msg.text:
sender = "BOT" if msg.from_id == bot.id else "USER"
conversation.append({
"sender": sender,
"time": msg.date.strftime('%Y-%m-%d %H:%M:%S'),
"text": msg.text,
"buttons": [[btn.text for btn in row] for row in msg.buttons] if msg.buttons else None
})2. Deep API Analysis
Intercept Callback Data:
from telethon.tl.functions.messages import GetBotCallbackAnswerRequest
# Get button callback data
for button in msg.reply_markup.rows:
if hasattr(button, 'data'):
callback_data = button.data.decode('utf-8', errors='ignore')
print(f"Callback: {callback_data}")Extract Web App URLs:
# Check for magic links, payment URLs, admin panels
for button in msg.buttons:
if hasattr(button, 'button') and hasattr(button.button, 'url'):
url = button.button.url
if 'magic' in url or 'admin' in url or 'api' in url:
print(f"Suspicious URL: {url}")3. Backend Discovery
Common Patterns:
- Magic links: /magic/go/{timestamp}/{user_id}
- API endpoints: /api/v1/..., /webhook/...
- Admin panels: /admin, /debug, /dashboard
Server Fingerprinting:
curl -I http://target-ip:port/
# Look for: Server header, framework version, error messagesEndpoint Fuzzing:
# Common API paths
/api /api/v1 /api/wallet /api/balance /api/deposit
/admin /debug /magic /webhook /callback4. Exploit Discovery
Common Vulnerability Classes:
- Premature Reward Distribution
- Reward given before full verification
- No rollback mechanism
- Missing state validation
- 2FA/Authentication Bypass
- Temporary 2FA setup → get reward → disable 2FA
- No continuous verification
- App password validation gaps
- Race Conditions
- Rapid button clicking
- Concurrent requests
- State synchronization issues
- Payment Approval Manipulation
- Webhook triggers on payment approval
- No completion verification
- Abandoned registration still rewards
- Referral/Reward Gaming
- Self-referral loops
- Multiple account exploitation
- Reward duplication
5. Exploit Documentation
Structure:
## Vulnerability Summary
- Type: [Premature Reward / Auth Bypass / Race Condition]
- Severity: [Low / Medium / High / Critical]
- Impact: [Financial loss / Data breach / Account takeover]
## Exploit Steps
1. Step-by-step reproduction
2. Required prerequisites
3. Expected outcome
## Technical Details
- Root cause analysis
- Code snippets (if available)
- Attack flow diagram
## Mitigation
- Recommended fixes
- Code patches
- Security best practicesTools and Techniques
Telethon API Methods
Message Inspection:
# Get conversation history
msgs = await client.get_messages(bot, limit=100)
# Filter for specific content
for msg in msgs:
if msg.buttons:
# Analyze button structure
if msg.text and 'reward' in msg.text.lower():
# Flag reward-related messagesCallback Testing:
# Test crafted callback data
test_payloads = [
b'admin', b'debug', b'wallet', b'claim',
b'{"action":"deposit","amount":9999}',
]
for payload in test_payloads:
try:
result = await client(GetBotCallbackAnswerRequest(
peer=bot, msg_id=msg.id, data=payload
))
if result.message:
print(f"Payload {payload} → {result.message}")
except Exception as e:
print(f"Payload {payload} → Error: {e}")Web API Security Testing
For testing backend APIs discovered during bot analysis:
Validation Testing
Test cases:
TEST_CASES = [
# Negative values
{"amount": -1, "price": 10},
# Zero values
{"amount": 0, "price": 10},
# Float where integer expected
{"amount": 0.1, "price": 10},
# Very large numbers (integer overflow)
{"amount": 2**63, "price": 10},
# SQL injection
{"amount": "1 OR 1=1", "price": 10},
{"amount": "1'; DROP TABLE users--", "price": 10},
# XSS injection
{"amount": "<script>alert(1)</script>", "price": 10},
# Null/undefined
{"amount": None, "price": 10},
# Type confusion
{"amount": "1", "price": "10"}, # String instead of number
{"amount": [1], "price": 10}, # Array instead of number
]Race Condition Testing
import concurrent.futures
def send_request():
return requests.post(
"https://target.com/api/endpoint",
headers=headers,
json={"amount": 1, "price": 10},
timeout=30
)
# Send 5 simultaneous requests
with concurrent.futures.ThreadPoolExecutor(max_workers=5) as executor:
futures = [executor.submit(send_request) for _ in range(5)]
results = [f.result() for f in concurrent.futures.as_completed(futures)]
success_count = sum(1 for r in results if r.status_code in (200, 201))
if success_count > 1:
print(f"🚨 RACE CONDITION! {success_count} requests succeeded")Authentication Testing
# Test 1: Expired token
headers = {"Authorization": "Bearer EXPIRED_TOKEN"}
resp = requests.get("https://target.com/api/me", headers=headers)
# Expected: 401 Unauthorized
# Test 2: Invalid token
headers = {"Authorization": "Bearer INVALID_TOKEN"}
resp = requests.get("https://target.com/api/me", headers=headers)
# Expected: 401 Unauthorized
# Test 3: Token from different user
headers = {"Authorization": "Bearer USER_A_TOKEN"}
resp = requests.get("https://target.com/api/users/USER_B_ID", headers=headers)
# Expected: 403 ForbiddenCommon Vulnerabilities
- Insufficient Input Validation — API accepts invalid data (negative numbers, SQL injection)
- Race Conditions — Multiple requests succeed when only one should
- Broken Authentication — Can access resources without valid token
- Broken Authorization — Can access other users' resources
- Business Logic Flaws — Can perform actions that violate business rules
See references/web-api-security-patterns.md for comprehensive testing methodology.
Backend Server Analysis
Flask/Werkzeug Detection:
# Check for debug mode
curl http://target/console
curl http://target/_debug_toolbar
# Common Flask paths
curl http://target/static/
curl http://target/admin/More skills from kevinnft/ai-agent-skills
- Aaddyosmani-tddDrives development with tests. Use when implementing any logic, fixing any bug, or changing any behavior. Use when you need to prove that code works, when a bug report arrives, or when you're about to modify existing functionality.
- AairtableAirtable REST API via curl. Records CRUD, filters, upserts.
- Aapi-and-interface-designGuides stable API and interface design. Use when designing APIs, module boundaries, or any public interface. Use when creating REST or GraphQL endpoints, defining type contracts between modules, or establishing boundaries between frontend and backend.
- Aapi-monitoring-botsBuild monitoring bots that poll APIs and send notifications on state changes (new listings, price alerts, status updates)
- Aapple-notesManage Apple Notes via memo CLI: create, search, edit.
- Aapple-remindersApple Reminders via remindctl: add, list, complete.
- Aarchitecture-diagramDark-themed SVG architecture/cloud/infra diagrams as HTML.
- AarxivSearch arXiv papers by keyword, author, category, or ID.
- Aascii-artASCII art: pyfiglet, cowsay, boxes, image-to-ascii.
- Aascii-videoASCII video: convert video/audio to colored ASCII MP4/GIF.
- AaudiocraftAudioCraft: MusicGen text-to-music, AudioGen text-to-sound.
- CaxolotlAxolotl: YAML LLM fine-tuning (LoRA, DPO, GRPO).