Atlas / MCP servers / leshchenko1979 / Fast Telegram

Fast TelegramBLOCK

mcp/leshchenko1979/fast-telegram

Telegram MCP gateway for AI agents: 8 tools, multi-tenant HTTP/stdio, MTProto

Verdict
BLOCK
Grade
F
Trust score
44 /100
Exposed tools
9 7r · 2w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
48
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Telegram MCP Server — Model Context Protocol (MCP) gateway for Telegram. 8 context-efficient tools, multi-tenant, MTProto bridge.

Try the Demo

  1. Open https://tg-mcp.l1979.ru/setup
  2. Scan the QR code from Telegram mobile (Settings → Devices → Scan QR) — no phone typing, no OTP, no 2FA. Or enter your phone number as fallback.
  3. Copy your Bearer token from the success page

Then choose your path:

MCP Client (AI assistants)

  • From the setup page, download the mcp.json file
  • Add the server to your AI client and ask: "send hello to my saved messages in telegram"

Direct API (curl)

  • Run the command below (replace TOKEN with yours):
curl -X POST "https://tg-mcp.l1979.ru/mtproto-api/messages.SendMessage" \
-H "Authorization: Bearer TOKEN" \
-H "Content-Type: application/json" \
-d '{"params": {"peer": "me", "message": "Hello!"}}'

[](https://python.org) [](https://opensource.org/licenses/MIT) [](https://github.com/leshchenko1979/fast-mcp-telegram) [](https://gatus.l1979.ru/endpoints/apps_fast-mcp-telegram) [](https://glama.ai/mcp/servers/leshchenko1979/fast-mcp-telegram)

How It Works

This server sits between your AI agent and Telegram's API:

Your agent → MCP/HTTP → this server → MTProto → Telegram

What it does: Authenticates you with Telegram (QR or phone/bot token), exposes 8 AI-friendly tools instead of 80+ micro-APIs, and bridges raw MTProto for power users. Multi-tenant — one server, ma

Read from source at commit 75e76faced69OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add fast-mcp-telegram --env API_HASH=${API_HASH} -- None fast-mcp-telegram==0.44.1
03

Exposed tools (9)

7 read · 2 write · 0 destructive.

ToolRiskDescription
auth_test_toolreadTest tool to verify authentication context.
edit_messagewriteEdit existing message in Telegram chat.
failing_decorator_toolreadTest tool that fails to test error handling in decorator chain.
get_messagesreadUnified message retrieval - search, browse, read by IDs, or get replies.
incorrectly_decorated_funcreadreturn
read_messagesreadRead Telegram messages
search_messages_globallyreadSearch across all Telegram chats.
send_messagewriteSend new message in Telegram chat.
test_decorator_toolreadTest tool that uses the full decorator chain.
04

Trust audit

BLOCKgrade F · trust 44/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (12 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/tools/messages/security.py:60
"169.254.169.254",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/tools/messages/security.py:61
"metadata.google.internal",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
collector/app/settings.py:7
"postgres://telemetry:telemetry@localhost:5432/telemetry",
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
collector/docker-compose.dev.yml:9
TELEMETRY_DSN: postgres://telemetry:telemetry@postgres:5432/telemetry
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli_setup.py:603
print("      headers: {Authorization: Bearer <token>}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/client/connection.py:196
logger.warning(f"Checkpoint/upload failed for {token[:8]}...: {e}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/client/connection.py:203
logger.warning(f"Disconnect failed for {token[:8]}...: {e}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/client/connection.py:253
logger.warning(f"Error disconnecting idle session {token[:8]}...: {e}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/client/connection.py:464
logger.info(f"Using local fallback for {token[:8]}...")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
acl.dev.yaml.example:4
# Create sessions via http://127.0.0.1:8765/setup after starting the ACL dev server.
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
collector/README.md:143
| `TELEMETRY_DSN` | production | `postgres://telemetry:telemetry@localhost:5432/telemetry` | PostgreSQL connection string |
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
collector/tests/test_e2e.py:40
return f"postgres://{pg_user}:{pg_pass}@{pg_host}:{pg_port}/{pg_db}"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
CONTRIBUTING.md:174
TOKEN="dev_acl_readonly_abcdefghijklmnopqrstuvwxz0"  # from acl.dev.yaml
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/server_components/server_card.py:192
return f'"{hashlib.md5(raw, usedforsecurity=False).hexdigest()}"'
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/unit/tools/test_url_security.py:70
for host in ["169.254.169.254", "metadata.google.internal"]:
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CLAUDE.md:37
- **Correct approach**: ACL enforces only with `SERVER_MODE=http-auth` and `ACL_ENABLED=true`; each bearer in `acl.dev.yaml` needs a matching `{token}.session` via `http://127.0.0.1:8765/setup`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONTRIBUTING.md:170
3. Create one session per profile at `http://127.0.0.1:8765/setup` (session files must match principal identifiers in `acl.dev.yaml`).
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONTRIBUTING.md:176
curl -sS -X POST "http://127.0.0.1:8765/v1/mcp" \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONTRIBUTING.md:205
Per-principal sessions for http-auth (including ACL profiles) are created at `http://127.0.0.1:8765/setup` while the server above is running. Each principal identifier in `acl.dev.yaml` needs a matchi
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/tools/messages/file_handling.py:95
decoded = base64.b64decode(payload, validate=True)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/utils/proxy.py:112
decoded = base64.b64decode(padded, validate=True)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
collector/requirements.txt
psycopg2-binary
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SECURITY.md:169
- **Session binding**: The server uses the Telegram session that minted the ticket to stream bytes; the HTTP client does not send session credentials.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/Installation.md:224
Optional **per-principal limits** on shared `http-auth` hosts: choose which chats each principal may use and whether it may send messages or call raw Telegram APIs. Clients still authenticate with Bea
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/Roadmap.md:140
| **Principal identifier forms** | **Admin ergonomics:** operators can key `principals:` entries by Telegram `@username` or numeric `user_id` instead of copying opaque Bearer strings — easier to assig
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 75e76faced69full audit observations/trust-audit/mcp-server/leshchenko1979__fast-telegram.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0875e76faced69BLOCKF44first audit
06

Questions

What is the Fast Telegram MCP server?

Telegram MCP gateway for AI agents: 8 tools, multi-tenant HTTP/stdio, MTProto

What tools does Fast Telegram expose?

9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Fast Telegram safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (44/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Fast Telegram need?

It reads API_HASH, BEARER_TOKEN_FOR_TESTING and TELEMETRY_PG_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Fast Telegram run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as fast-mcp-telegram.

How current is this page?

The grade is for one exact copy of the source (75e76faced69), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement