Atlas / MCP servers / mcp-telegram / Telegram AI

Telegram AISAFE

mcp/mcp-telegram/telegram-ai

Telegram MCP server: connect your personal Telegram account to Claude, ChatGPT, Cursor and any MCP client. 182 tools over MTProto. Self-host with npx or Docker, or use the hosted version.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
182 117r · 51w · 14d
Transport
stdio · streamable-http
License
MIT
Stars
46
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@overpod/mcp-telegram) [](https://www.npmjs.com/package/@overpod/mcp-telegram) [](https://nodejs.org/) [](https://www.typescriptlang.org/) [](https://modelcontextprotocol.io/) [](LICENSE) [](https://glama.ai/mcp/servers/overpod/mcp-telegram)

[📖 Documentation](https://mcp-telegram.github.io/mcp-telegram/) · [☁️ Cloud version](https://mcp-telegram.com) — connect Telegram to Claude.ai or ChatGPT in 30 seconds with QR code, no API keys needed.

Telegram MCP Server — a Model Context Protocol server that connects AI assistants like Claude and ChatGPT to Telegram via the MTProto protocol. Unlike bots, this runs as a userbot -- it operates under your personal Telegram account using GramJS, giving full access to your chats, contacts, and message history.

Features

  • Comprehensive tool coverage -- the most full-featured Telegram MCP server available
  • MTProto protocol -- direct Telegram API access, not the limited Bot API
  • Userbot -- operates as your personal account, not a bot
  • Full-featured -- messaging, reactions, polls, scheduled messages, stickers, media, contacts, and more
  • Forum Topics -- list topics, read per-topic messages, send to specific topics, per-topic unread
Read from source at commit e920d1717cebOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-telegram --env TELEGRAM_API_ID=${TELEGRAM_API_ID} --env TELEGRAM_API_HASH=${TELEGRAM_API_HASH} -- npx -y @overpod/[email protected]
03

Exposed tools (182)

117 read · 51 write · 14 destructive. Blast radius: 14 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
telegram-activate-stealth-moderead
telegram-add-contactwrite
telegram-approve-join-requestread
telegram-archive-chatread
telegram-ban-userread
telegram-block-userread
telegram-change-stars-subscriptionread
telegram-clear-draftsdestructive
telegram-clear-recent-emoji-statusesdestructive
telegram-close-pollread
telegram-convert-star-giftread
telegram-create-business-chat-linkwrite
telegram-create-folderwrite
telegram-create-groupwrite
telegram-create-invite-linkwrite
telegram-create-pollwrite
telegram-create-topicwrite
telegram-delete-business-chat-linkdestructive
telegram-delete-fact-checkdestructive
telegram-delete-folderdestructive
telegram-delete-messagedestructive
telegram-delete-profile-photodestructive
telegram-delete-scheduleddestructive
telegram-delete-storiesdestructive
telegram-delete-topicdestructive
telegram-download-mediaread
telegram-edit-business-chat-linkwrite
telegram-edit-fact-checkwrite
telegram-edit-folderwrite
telegram-edit-groupwrite
telegram-edit-messagewrite
telegram-edit-storywrite
telegram-edit-topicwrite
telegram-export-story-linkread
telegram-forward-messageread
telegram-get-admin-logread
telegram-get-all-storiesread
telegram-get-available-star-giftsread
telegram-get-boosts-listread
telegram-get-boosts-statusread
telegram-get-broadcast-statsread
telegram-get-business-chat-linksread
telegram-get-channel-updatesread
telegram-get-chat-foldersread
telegram-get-chat-inforead
telegram-get-chat-membersread
telegram-get-contact-requestsread
telegram-get-contactsread
telegram-get-discussion-messageread
telegram-get-draftsread
telegram-get-fact-checkread
telegram-get-global-privacy-settingsread
telegram-get-group-callread
telegram-get-group-call-participantsread
telegram-get-groups-for-discussionread
telegram-get-installed-stickersread
telegram-get-invite-linksread
telegram-get-megagroup-statsread
telegram-get-message-buttonsread
telegram-get-message-linkread
telegram-get-message-read-participantsread
telegram-get-my-boostsread
telegram-get-my-roleread
telegram-get-outbox-read-dateread
telegram-get-paid-reaction-privacyread
telegram-get-peer-storiesread
telegram-get-poll-resultsread
telegram-get-poll-votersread
telegram-get-profileread
telegram-get-profile-photoread
telegram-get-quick-repliesread
telegram-get-quick-reply-messagesread
telegram-get-reactionsread
telegram-get-recent-reactionsread
telegram-get-recent-stickersread
telegram-get-repliesread
telegram-get-saved-dialogsread
telegram-get-saved-musicread
telegram-get-saved-star-giftsread
telegram-get-scheduledread
telegram-get-sessionsread
telegram-get-stars-statusread
telegram-get-stars-subscriptionsread
telegram-get-stars-topup-optionsread
telegram-get-stars-transactionsread
telegram-get-stateread
telegram-get-sticker-setwrite
telegram-get-stories-archiveread
telegram-get-stories-by-idread
telegram-get-story-viewsread
telegram-get-suggested-foldersread
telegram-get-top-reactionsread
telegram-get-transcriptionread
telegram-get-unreadread
telegram-get-unread-mentionsread
telegram-get-unread-reactionsread
telegram-get-updatesread
telegram-get-web-previewread
telegram-inline-queryread
telegram-inline-query-sendwrite
telegram-invite-to-groupread
telegram-join-chatread
telegram-kick-userread
telegram-leave-groupread
telegram-list-chatsread
telegram-list-emoji-statusesread
telegram-list-topicsread
telegram-loginread
telegram-logoutread
telegram-mark-as-readread
telegram-mark-dialog-unreadread
telegram-mute-chatread
telegram-pin-chatread
telegram-pin-messageread
telegram-press-buttonread
telegram-rate-transcriptionread
telegram-react-to-storyread
telegram-read-messagesread
telegram-read-storiesread
telegram-read-topic-messagesread
telegram-remove-admindestructive
telegram-reorder-foldersread
telegram-report-spamread
telegram-report-storyread
telegram-resolve-business-chat-linkread
telegram-revoke-invite-linkdestructive
telegram-save-draftwrite
telegram-save-star-giftwrite
telegram-search-chatsread
telegram-search-globalread
telegram-search-messagesread
telegram-search-sticker-setsread
telegram-send-albumwrite
telegram-send-contactwrite
telegram-send-dicewrite
telegram-send-filewrite
telegram-send-locationwrite
telegram-send-messagewrite
telegram-send-paid-reactionwrite
telegram-send-reactionwrite
telegram-send-scheduledwrite
telegram-send-stickerwrite
telegram-send-storywrite
telegram-send-typingwrite
telegram-send-venuewrite
telegram-send-video-notewrite
telegram-send-voicewrite
telegram-set-adminwrite
telegram-set-auto-deletedestructive
telegram-set-birthdaywrite
telegram-set-business-awaywrite
telegram-set-business-greetingwrite
telegram-set-business-hourswrite
telegram-set-business-introwrite
telegram-set-business-locationwrite
telegram-set-chat-permissionswrite
telegram-set-chat-reactionswrite
telegram-set-default-reactionwrite
telegram-set-emoji-statuswrite
telegram-set-global-privacy-settingswrite
telegram-set-personal-channelwrite
telegram-set-privacywrite
telegram-set-profile-colorwrite
telegram-set-profile-photowrite
telegram-set-slow-modewrite
telegram-statusread
telegram-terminate-sessiondestructive
telegram-toggle-anti-spamread
telegram-toggle-channel-signaturesread
telegram-toggle-folder-tagsread
telegram-toggle-forum-moderead
telegram-toggle-paid-reaction-privacyread
telegram-toggle-prehistory-hiddenread
telegram-toggle-story-pinnedread
telegram-toggle-story-pinned-to-topread
telegram-transcribe-audioread
telegram-translate-messageread
telegram-unban-userread
telegram-unblock-userread
telegram-unpin-messageread
telegram-update-profilewrite
telegram-vote-pollread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (16)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
telegram-clear-drafts, telegram-clear-recent-emoji-statuses, telegram-delete-business-chat-link, telegram-delete-fact-check, telegram-delete-folder, telegram-delete-message, telegram-delete-profile-ph
Why it matters. 14 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/lock.ts:36
return WIN_PIPE_PREFIX + createHash("sha1").update(normalized).digest("hex").slice(0, 32);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs/.vitepress/cache/deps/vitepress___@vue_devtools-api.js:31
"../../node_modules/.pnpm/[email protected]_@[email protected]_@[email protected][email protected][email protected]_96eb05a9d65343021e53791dd83f3773/node_modules/tsup/assets/esm_shims.js"() {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs/.vitepress/cache/deps/vitepress___@vue_devtools-api.js:36
"../../node_modules/.pnpm/[email protected]/node_modules/rfdc/index.js"(exports, module) {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs/.vitepress/cache/deps/vitepress___@vue_devtools-api.js:557
"../../node_modules/.pnpm/[email protected]_@[email protected]_@[email protected][email protected][email protected]_96eb05a9d65343021e53791dd83f3773/node_modules/tsup/assets/esm_shims.js"() {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs/.vitepress/cache/deps/vitepress___@vue_devtools-api.js:562
"../../node_modules/.pnpm/[email protected]/node_modules/speakingurl/lib/speakingurl.js"(exports, module) {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
docs/.vitepress/cache/deps/vitepress___@vue_devtools-api.js:2089
"../../node_modules/.pnpm/[email protected]/node_modules/speakingurl/index.js"(exports, module) {
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/__tests__/send-media.test.ts:74
assert.strictEqual(isSafeAbsolutePath("https://169.254.169.254/latest/meta-data/"), false);
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/send-media.test.ts:74
assert.strictEqual(isSafeAbsolutePath("https://169.254.169.254/latest/meta-data/"), false);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, big-integer, dotenv, qrcode, telegram, zod, @biomejs/biome, @types/node
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:131
* **tools:** curate stars/press-button/report-story output to cut response tokens ([06d3fa1](https://github.com/mcp-telegram/mcp-telegram/commit/06d3fa113eb287237aff6c4d866785b06e9cd660))
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:530
- **`TelegramService.logOut()` hardened** — server-revoke and client-destroy are now split: a successful `auth.LogOut` returns `true` even if `client.destroy()` throws (previously misreported "not con
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
assets/demo.gif
assets/demo.gif
Why it matters. 2053974 bytes not read
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:17
**Telegram MCP Server** — a Model Context Protocol server that connects AI assistants like Claude and ChatGPT to Telegram via the MTProto protocol. Unlike bots, this runs as a **userbot** -- it operat
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/getting-started/login.md:58
- The session allows full access to your Telegram account — treat it like a password

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha e920d1717cebfull audit observations/trust-audit/mcp-server/mcp-telegram__telegram-ai.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09e920d1717cebSAFEB89first audit
06

Questions

What is the Telegram AI MCP server?

Telegram MCP server: connect your personal Telegram account to Claude, ChatGPT, Cursor and any MCP client. 182 tools over MTProto. Self-host with npx or Docker, or use the hosted version.

What tools does Telegram AI expose?

182 in total: 117 read-only, 51 that write, and 14 that can delete or overwrite (telegram-clear-drafts, telegram-clear-recent-emoji-statuses, telegram-delete-business-chat-link, telegram-delete-fact-check, telegram-delete-folder). Every one is listed on this page with its risk.

Is Telegram AI safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 14 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Telegram AI need?

It reads TELEGRAM_2FA_PASSWORD, TELEGRAM_API_HASH, TELEGRAM_API_ID, TELEGRAM_PROXY_PASSWORD and TELEGRAM_PROXY_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Telegram AI run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @overpod/mcp-telegram at 1.43.4.

How current is this page?

The grade is for one exact copy of the source (e920d1717ceb), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement