telegram-miniapp-security-auditorAudit Telegram Mini App projects for launch safety before connecting bot tokens or public channels. Use when Codex needs to review a Telegram WebApp/Mini App...
Install via ClawdBot CLI:
clawdbot install zack-dev-cm/telegram-miniapp-security-auditorGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/zack-dev-cm/telegram-miniapp-security-auditorAudited Apr 26, 2026 · audit v1.0
Generated May 23, 2026
A startup is about to launch a Telegram Mini App with a connected bot token and public channel. The security auditor scans the project for hardcoded tokens, missing server-side initData validation, and insecure CORS settings. It generates a report with PASS/REVIEW/BLOCK decisions, ensuring no critical vulnerabilities go live.
A developer packages a Telegram Mini App as an OpenClaw/Codex skill and needs a security audit before publishing. The auditor checks for hardcoded secrets, admin endpoints without guards, and unsafe innerHTML usage. It also integrates with TrustClaw for trust verification, ensuring the skill is safe for reuse.
A team is following a BotFather launch runbook and must ensure the Mini App meets security requirements. The auditor validates server-side initData validation, no committed tokens, and proper admin endpoint protection. It produces a markdown report that can be included in the runbook as evidence.
A FastAPI backend for a Telegram Mini App uses CORS and admin endpoints. The auditor scans for wildcard CORS (with credentials) and unprotected admin routes. It flags BLOCK for missing authorization, prompting developers to add proper guards before deploying to production.
A Mini App relies on Telegram initData for user identity. The auditor checks for client-side-only validation, which is a BLOCK risk. It then verifies if the backend performs server-side validation. The report helps developers understand that initData must be validated on the server to prevent impersonation.
Offer recurring security audits for Telegram Mini Apps on a subscription basis. Developers can run the auditor in CI/CD pipelines to catch issues before each release. Revenue from monthly/annual subscriptions, with tiered pricing based on frequency and report depth.
Provide a one-time security audit service for projects launching on Telegram. Clients pay a flat fee per audit, receiving a detailed markdown report with findings and recommendations. Additional charges for manual verification of REVIEW findings.
License the auditor as a plugin for CI/CD tools (e.g., GitHub Actions, GitLab CI). Developers can automate security checks without manual intervention. Revenue from enterprise licensing or per-seat pricing with premium support.
💬 Integration Tip
Integrate the auditor into your existing CI/CD pipeline by running the script as a step, and parse the JSON report to fail the build on BLOCK findings. For manual reviews, use the Markdown output as a checklist item for launch readiness.
Scored Jul 25, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...