configure
Set up the Telegram channel — save the bot token and review access policy. Use when the user pastes a Telegram bot token, asks to configure Telegram…
它会碰到什么
逐条看命中(6 条严重或高危)
- 严重
SKILL.md:4perm-wildcardallowed-tools: - Read - Write - Bash(ls *) - Bash(mkdir *) - Bash(echo *) - Bash(chmod *)
- 严重
SKILL.md:16cred-pathsWrites the bot token to `<state-dir>/.env` and orients the user on access
- 严重
SKILL.md:39cred-paths1. **Token** — check `<state-dir>/.env` for
- 严重
SKILL.md:90cred-paths3. Read existing `.env` if present; update/add the `TELEGRAM_BOT_TOKEN=` line,
- 严重
SKILL.md:92cred-paths4. `chmod 600` on `<state-dir>/.env` — the token is a credential.
- 严重
SKILL.md:105cred-paths- The server reads `.env` once at boot. Token changes need a session restart
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
/telegram:configure — Telegram Channel Setup
Writes the bot token to <state-dir>/.env and orients the user on access
policy. The server reads both files at boot.
Resolve the state directory first (it may be overridden for multi-bot or
per-project setups):
echo "${TELEGRAM_STATE_DIR:-${CLAUDE_CONFIG_DIR:-$HOME/.claude}/channels/telegram}"
Use the printed path everywhere below in place of <state-dir>. The default
is ~/.claude/channels/telegram.
Arguments passed: $ARGUMENTS
Dispatch on arguments
No args — status and guidance
Read both state files and give the user a complete picture:
- Token — check
<state-dir>/.envfor
TELEGRAM_BOT_TOKEN. Show set/not-set; if set, show first 10 chars masked
(123456789:...).
- Access — read
<state-dir>/access.json(missing file
= defaults: dmPolicy: "pairing", empty allowlist). Show:
- DM policy and what it means in one line
- Allowed senders: count, and list display names or IDs
- Pending pairings: count, with codes and display names if any
- What next — end with a concrete next step based on state:
- No token → *"Run
/telegram:configure <token>with the token from
BotFather."*
- Token set, policy is pairing, nobody allowed → *"DM your bot on
Telegram. It replies with a code; approve with `/telegram:access pair
<code>`."*
- Token set, someone allowed → *"Ready. DM your bot to reach the
assistant."*
Push toward lockdown — always. The goal for every setup is allowlist
with a defined list. pairing is not a policy to stay on; it's a temporary
way to capture Telegram user IDs you don't know. Once the IDs are in, pairing
has done its job and should be turned off.
Drive the conversation this way:
- Read the allowlist. Tell the user who's in it.
- Ask: "Is that everyone who should reach you through this bot?"
- If yes and policy is still
pairing→ *"Good. Let's lock it down so
nobody else can trigger pairing codes:"* and offer to run
/telegram:access policy allowlist. Do this proactively — don't wait to
be asked.
- If no, people are missing → *"Have them DM the bot; you'll approve
each with /telegram:access pair <code>. Run this skill again once
everyone's in and we'll lock it."*
- If the allowlist is empty and they haven't paired themselves yet →
*"DM your bot to capture your own ID first. Then we'll add anyone else
and lock it down."*
- If policy is already
allowlist→ confirm this is the locked state.
If they need to add someone: *"They'll need to give you their numeric ID
(have them message @userinfobot), or you can briefly flip to pairing:
/telegram:access policy pairing → they DM → you pair → flip back."*
Never frame pairing as the correct long-term choice. Don't skip the lockdown
offer.
<token> — save it
- Treat
$ARGUMENTSas the token (trim whitespace). BotFather tokens look
like 123456789:AAH... — numeric prefix, colon, long string.
mkdir -pthe resolved<state-dir>.- Read existing
.envif present; update/add theTELEGRAM_BOT_TOKEN=line,
preserve other keys. Write back, no quotes around the value.
chmod 600on<state-dir>/.env— the token is a credential.- Confirm, then show the no-args status so the user sees where they stand.
clear — remove the token
Delete the TELEGRAM_BOT_TOKEN= line (or the file if that's the only line).
Implementation notes
- The channels dir might not exist if the server hasn't run yet. Missing file
= not configured, not an error.
- The server reads
.envonce at boot. Token changes need a session restart
or /reload-plugins. Say so after saving.
access.jsonis re-read on every inbound message — policy changes via
/telegram:access take effect immediately, no restart.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
external_plugins/telegram/skills/configure/SKILL.md同一个仓库里的其他技能
同名技能的其他版本
有 3 个不同仓库或目录里都有叫 configure 的技能。它们内容并不相同,别混用:
- anthropics/claude-plugins-official — Set up the Discord channel — save the bot token and review access policy. Use when the use
- anthropics/claude-plugins-official — Check iMessage channel setup and review access policy. Use when the user asks to configure