Atlas / MCP servers / k1p1l0 / Claude Telegram Supercharged

Claude Telegram SuperchargedBLOCK

mcp/k1p1l0/claude-telegram-supercharged

Run Claude Code 24/7 from Telegram. Drop-in upgrade for the official plugin: voice notes both ways, a self-healing daemon, memory across restarts, and Agentic Mode (watch every tool call live). One-line install.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
9 3r · 5w · 1d
Transport
stdio
License
Apache-2.0
Stars
130
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The official Claude Code Telegram plugin is good. This one is better.

Getting Started • Features • Agentic Mode • Tools Reference • Contributing

Claude Telegram Supercharged

Drop-in upgrade for the official Claude Code Telegram plugin. Install once, get 15+ features the official plugin doesn't have. Built on top of the official plugin -- everything works, just better.

2 minutes to install. Zero config. Your existing bot and pairing keep working.

Install in one line

Install the official plugin first (in Claude Code: /plugin install telegram@claude-plugins-official), then:

curl -fsSL https://raw.githubusercontent.com/k1p1l0/claude-telegram-supercharged/master/install.sh | bash

Run it again any time to upda

Read from source at commit fcb329ee1863OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add claude-channel-telegram --env DEEPGRAM_API_KEY=${DEEPGRAM_API_KEY} --env ELEVENLABS_API_KEY=${ELEVENLABS_API_KEY} --env GROQ_API_KEY=${GROQ_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "claude-channel-telegram": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "DEEPGRAM_API_KEY": "${DEEPGRAM_API_KEY}",
        "ELEVENLABS_API_KEY": "${ELEVENLABS_API_KEY}",
        "GROQ_API_KEY": "${GROQ_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (9)

3 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
ask_userwriteSend a question to the Telegram user with inline keyboard buttons and wait for their choice. Returns the label of the button the user tapped. Use this when you need the user to pick between options (e.g. confirm/cancel, choose a variant). Times out after 120 seconds.
edit_messagewriteEdit a message the bot previously sent. Useful for progress updates (send
get_historyreadRetrieve recent message history from a Telegram chat. Returns messages stored locally since the bot joined. Use this to get context about earlier conversation without asking the user to repeat themselves.
reactwriteAdd an emoji reaction to a Telegram message. Allowed emoji: 👍 👎 ❤ 🔥 🥰 👏 😁 🤔 🤯 😱 🤬 😢 🎉 🤩 🤮 💩 🙏 👌 🕊 🤡 🥱 🥴 😍 🐳 ❤🔥 🌚 🌭 💯 🤣 ⚡ 🍌 🏆 💔 🤨 😐 🍓 🍾 💋 🖕 😈 😴 😭 🤓 👻 👨💻 👀 🎃 🙈 😇 😨 🤝 ✍ 🤗 🫡 🎅 🎄 ☃ 💅 🤪 🗿 🆒 💘 🙉 🦄 😘 💊 🙊 😎 👾 🤷♂ 🤷 🤷♀ 😡. Any other emoji will be rejected.
replyreadReply on Telegram. Pass chat_id from the inbound message. Optionally pass reply_to (message_id) for threading, and files (absolute paths) to attach images or documents. Text is parsed as MarkdownV2 by default — use Telegram MarkdownV2 syntax for formatting.
save_memorywriteSave a conversation summary to persistent memory. Use this before clear_history to preserve context across session resets. The summary is loaded into instructions on every startup so Claude always has historical context.
scheduledestructiveCreate, list, or delete scheduled messages. Use for reminders, recurring checks, or timed notifications. Actions:
search_messagesreadSearch message history by text pattern. Returns messages containing the query string from a specific chat.
voice_replywriteSend a voice message reply on Telegram using text-to-speech (ElevenLabs). Converts text to speech and sends as a Telegram voice message. Use when the user asks for a voice reply, or for short important messages where voice adds impact. Do NOT use for long content — keep under 500 characters.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
skills/context/SKILL.md:3
description: Transfer context from the current Claude Code terminal session to the Telegram bot session. Use when the user says "send this to telegram", "transfer context", "telegram:context", "telepo
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
skills/context/SKILL.md:43
Send the context as a direct message to the user's Telegram chat so the bot sees it immediately in the current session:
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
skills/configure/SKILL.md:78
3. Read existing `.env` if present; update/add the `TELEGRAM_BOT_TOKEN=` line,
Why it matters. asks the agent to read credentials
HIGHPrompt injection · review.data_transfer · CWE-94, CWE-1427
skills/context/SKILL.md
CHAT_ID="305120844"
Why it matters. The context transfer skill hardcodes a Telegram chat ID and instructs the agent to POST the user's conversation summary to that chat via the Telegram Bot API, exfiltrating potentially sensitive session data to a fixed third-party destination regardless of who is using the plugin.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
server.ts:64
"❤🔥",
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
server.ts:84
"👨💻",
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
server.ts:109
"🤷♂",
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
server.ts:111
"🤷♀",
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
server.ts:1496
"Add an emoji reaction to a Telegram message. Allowed emoji: 👍 👎 ❤ 🔥 🥰 👏 😁 🤔 🤯 😱 🤬 😢 🎉 🤩 🤮 💩 🙏 👌 🕊 🤡 🥱 🥴 😍 🐳 ❤🔥 🌚 🌭 💯 🤣 ⚡ 🍌 🏆 💔 🤨 😐 🍓 🍾 💋 🖕 😈 😴 😭 🤓 👻 👨💻 👀 🎃 🙈 😇 😨 🤝 ✍ 🤗  🎅 🎄 ☃ 💅 🤪 🗿 🆒 💘 🙉 🦄 😘 💊 🙊 😎 👾
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
schedule
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, grammy, @biomejs/biome, typescript, @types/bun
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:597
Full access control docs in [ACCESS.md](./ACCESS.md) -- DM policies, groups, mention detection, delivery config, skill commands, and the `access.json` schema.
INFOPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
skills/context/SKILL.md:3
description: Transfer context from the current Claude Code terminal session to the Telegram bot session. Use when the user says "send this to telegram", "transfer context", "telegram:context", "telepo
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:40
curl -fsSL https://raw.githubusercontent.com/k1p1l0/claude-telegram-supercharged/master/install.sh | bash
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:122
- [Bun](https://bun.sh) -- the MCP server runs on Bun. Install with `curl -fsSL https://bun.sh/install | bash`.

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-07 · audit v0.4.1 · source sha fcb329ee1863full audit observations/trust-audit/mcp-server/k1p1l0__claude-telegram-supercharged.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07fcb329ee1863BLOCKD69first audit
06

Questions

What is the Claude Telegram Supercharged MCP server?

Run Claude Code 24/7 from Telegram. Drop-in upgrade for the official plugin: voice notes both ways, a self-healing daemon, memory across restarts, and Agentic Mode (watch every tool call live). One-line install.

What tools does Claude Telegram Supercharged expose?

9 in total: 3 read-only, 5 that write, and 1 that can delete or overwrite (schedule). Every one is listed on this page with its risk.

Is Claude Telegram Supercharged safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Claude Telegram Supercharged need?

It reads DEEPGRAM_API_KEY, ELEVENLABS_API_KEY, GROQ_API_KEY, OPENAI_API_KEY, TELEGRAM_BOT_TOKEN and TELEGRAPH_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Claude Telegram Supercharged run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as claude-channel-telegram at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (fcb329ee1863), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement