Atlas / MCP servers / kfastov / Tgcli

TgcliCAUTION

mcp/kfastov/tgcli

Telegram user console client and archiver

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
38 37r · 1w · 0d
Transport
streamable-http
License
MIT
Stars
43
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Telegram CLI with background sync and an optional MCP server for your personal account (MTProto, not bot API).

Installation

npm install -g @kfastov/tgcli
brew install kfastov/tap/tgcli

Authentication

Get Telegram API credentials:

  1. Go to https://my.telegram.org/apps
  2. Log in with your phone number
  3. Create a new application
  4. Copy api_id and api_hash

Then authenticate:

tgcli auth

Quick start

tgcli auth
tgcli sync --follow
tgcli messages list --chat @username --limit 20
tgcli messages search "course" --chat @channel --source archive
tgcli send text --to @username --message "hello"
tgcli server

Commands

tgcli auth           Authentication and session setup
tgcli config         View and edit config
tgcli sync           Archive backfill and realtime sync
tgcli server         Run background sync service (MCP optional)
tgcli service        Install/start/stop/status/logs for background service
tgcli channels       List/search channels
tgcli messages       List/search messages
tgcli send           Send text or files
tgcli media          Download media
tgcli topics         Forum topics
tgcli tags           Channel tags
tgcli metadata       Channel metadata cache
tgcli contacts       Contacts and people
tgcli groups         Group management
tgcli doctor         Diagnostics and sanity checks

Use tgcli [command] --help for details. Add --json for machine-readable output.

MCP (optional)

Enable it via config:

tgcli config set mcp.enabled true

By default the server binds to http://127.0.0.1:8080/mcp. To change it:

tgcli config set mcp.host 127.0.0.1
tgcli config set mcp.port 8080

Then run tgcli server and point your client at the configured address.

Configuration & Store

The tgcli store lives in the OS app-data directory and contains config.json, sessions, and messages.db. Override the location with TGCLI_STORE.

Legacy version: s

Read from source at commit 3cc5b904b81aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add tgcli -- npx -y @kfastov/[email protected]
claude-desktop
{
  "mcpServers": {
    "tgcli": {
      "command": "npx",
      "args": [
        "-y",
        "@kfastov/[email protected]"
      ]
    }
  }
}
03

Exposed tools (38)

37 read · 1 write · 0 destructive.

ToolRiskDescription
autoTagChannelsreadAuto-tags channels based on title, username, and cached metadata.
contactsAliasRemovereadRemoves alias for a contact.
contactsAliasSetreadSets an alias for a contact.
contactsGetreadReturns a contact profile from the local store.
contactsNotesSetreadSets notes for a contact.
contactsSearchreadSearches contacts/users with aliases, tags, and notes.
contactsTagsAddreadAdds tags to a contact.
contactsTagsRemovereadRemoves tags from a contact.
getChannelMetadatareadReturns cached metadata for a channel.
getSyncedMessageStatsreadReturns summary statistics for stored messages in a channel.
groupsInforeadFetches group information and metadata.
groupsInviteLinkGetreadGets the primary invite link for a group.
groupsInviteLinkRevokereadRevokes the primary invite link for a group.
groupsJoinreadJoins a group using an invite link or code.
groupsLeavereadLeaves a group chat or channel.
groupsListreadLists group chats and supergroups.
groupsMembersAddreadAdds members to a group.
groupsMembersRemovereadRemoves members from a group.
groupsRenamereadRenames a group chat or supergroup.
listActiveChannelsreadLists dialogs tracked in the local archive registry.
listChannelTagsreadList tags attached to a channel.
listChannelsreadLists available Telegram dialogs for the authenticated account, including unread message counts.
listMessageSyncJobswriteLists tracked message sync jobs and their current status.
listTaggedChannelsreadList channels that carry a specific tag.
markChannelReadreadMarks a Telegram channel as read up to the specified message ID.
mediaDownloadreadDownloads media from a message to a local file.
messagesContextreadReturns surrounding messages for a target message.
messagesGetreadFetches a specific message from the archive or live Telegram API.
messagesListreadLists messages from the archive or live Telegram API.
messagesSearchreadSearches messages across the archive or live Telegram API.
messagesSendreadSends a text message to a channel or chat.
messagesSendFilereadSends a file with an optional caption.
refreshChannelMetadatareadFetches and caches extended metadata for channels.
scheduleMessageSyncreadSchedules a background job to archive channel messages locally.
searchChannelsreadSearches dialogs by title or username.
setChannelTagsreadAssign tags to a channel for later cross-channel search.
topicsListreadLists forum topics for a supergroup.
topicsSearchreadSearches forum topics by title.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (4 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
core/control-client.js:75
return `http://127.0.0.1:${control.port}${pathname}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
core/control-server.js:89
url = new URL(req.url ?? '', 'http://127.0.0.1');
MEDIUMAuth / authz · mcp.remote_no_auth · CWE-287, CWE-862
streamable-http
Why it matters. a network transport with no auth environment variable found
Fix. require a token
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/folders.test.js:550
await expect(tc.joinChatlist('https://t.me/addlist/abc/../../evil')).rejects.toThrow('Invalid chatlist link');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:70
By default the server binds to `http://127.0.0.1:8080/mcp`. To change it:
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/control-client.test.js:81
expect(url).toBe('http://127.0.0.1:8765/control/ping');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/control-client.test.js:108
expect(url).toBe('http://127.0.0.1:8765/control/backfill');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @mtcute/core, @mtcute/node, better-sqlite3, commander, qrcode, vitest
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
AGENTS.md:26
- Add coverage when extending `telegram-client.js` or `message-sync-service.js` by mocking MTProto responses to validate session reuse and message archiving.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 3cc5b904b81afull audit observations/trust-audit/mcp-server/kfastov__tgcli.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-083cc5b904b81aCAUTIONB89first audit
06

Questions

What is the Tgcli MCP server?

Telegram user console client and archiver

What tools does Tgcli expose?

38 in total: 37 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Tgcli safe to connect to an agent?

With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Tgcli need?

No credential environment variables were found in its source, so it appears to need none.

How does Tgcli run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @kfastov/tgcli at 2.2.3.

How current is this page?

The grade is for one exact copy of the source (3cc5b904b81a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement