跳到主要内容
知仓学习社ZHICANG

telegram-bot-messaging

Send Telegram messages, files, and alerts via bot API; ask questions with inline buttons and wait for the answer. Supports multiple bots, named chat…

写文件联网严重 0 · 高危 6sickn33/agentic-awesome-skills

它会碰到什么

扫了多少3 个文本文件,26 KB
它会碰到什么写文件联网
命中总数9 处
命中统计严重 0 · 高 6 · 中 0 · 低 3
逐条看命中(6 条严重或高危)
  • README.md:156identity-config-write
    "hooks": {
  • README.md:157identity-config-write
    "Notification": [{"hooks": [{"type": "command",
  • README.md:159identity-config-write
    "Stop": [{"hooks": [{"type": "command",
  • SKILL.md:74identity-config-write
    "hooks": {
  • SKILL.md:75identity-config-write
    "Notification": [{"hooks": [{"type": "command",
  • SKILL.md:77identity-config-write
    "Stop": [{"hooks": [{"type": "command",

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Telegram

When to Use

  • Use when you need to send a Telegram message, file, or alert from a workflow, hook, cron job, or CI pipeline
  • Use when a long-running task should notify you or ask for approval on your phone (inline-button questions that wait for the answer)
  • Use when wiring "notify me when done" or "ask me before proceeding" behavior into automated sessions

Send updates, alerts, and files to Telegram; read replies; run ask-and-wait

approval flows. Pure bash + curl + jq — no install beyond a bot token.

First run: bash scripts/telegram.sh setup (guided BotFather walkthrough).

Safety Gate

Before setup, sending a message or file, reading replies, or enabling a hook, obtain the

user's explicit approval for the target chat, bot account, and exact content or file. Never

send workspace, customer, credential, or secret data automatically. Treat a token as a secret:

do not echo it, commit it, or place it in shell history.

Commands

bash scripts/telegram.sh send "Deploy finished ✅"                    # basic alert
bash scripts/telegram.sh send "low priority" --silent                # no notification sound
bash scripts/telegram.sh send "*bold* alert" --format md             # MarkdownV2 (falls back to plain)
bash scripts/telegram.sh send "hi" --to alerts --bot work            # named target + named bot
bash scripts/telegram.sh file report.pdf "Q3 report"                 # document (photos auto-detected)
bash scripts/telegram.sh read                                        # new incoming messages since last read
ANSWER=$(bash scripts/telegram.sh ask "Deploy to prod?" --options "Yes,No" --timeout 300)
# exit 0 = answered (stdout = answer), 2 = timeout

Config

Env vars win, then ~/.config/telegram/config (mode 600):

TELEGRAM_BOT_TOKEN=123:ABC...     # default bot
TELEGRAM_CHAT_ID=987654321        # default target
BOT_ALERTS_TOKEN=456:DEF...       # --bot alerts   (add via: setup --bot alerts)
TARGET_FAMILY=-100987...          # --to family    (any chat/group/channel id)
TELEGRAM_APPROVER_IDS=123456789   # default group approver user IDs (comma-separated)
APPROVERS_FAMILY=123456789,987654321 # approvers for --to family (overrides default)

Replies and answers are only accepted from configured chat IDs. Private chats preserve the

direct-chat behavior (the sender user ID must equal the chat ID). Because a group chat ID is

shared by every member, ask fails closed for groups unless TELEGRAM_APPROVER_IDS or the

target-specific APPROVERS_<NAME> explicitly lists the Telegram user IDs allowed to answer.

Claude Code hooks (settings.json)

Ping your phone when Claude needs input, and when it finishes:

{
  "hooks": {
    "Notification": [{"hooks": [{"type": "command",
      "command": "bash ~/.claude/skills/telegram/scripts/telegram.sh send \"🔔 Claude needs input in $(basename \\\"$PWD\\\")\""}]}],
    "Stop": [{"hooks": [{"type": "command",
      "command": "bash ~/.claude/skills/telegram/scripts/telegram.sh send \"✅ Claude finished in $(basename \\\"$PWD\\\")\" --silent"}]}]
  }
}

Approval gate in any script/automation:

if [ "$(bash scripts/telegram.sh ask 'Deploy to prod?' --options 'Yes,No')" = "Yes" ]; then
  ./deploy.sh
fi

Limitations

  • Telegram is a third-party service: message and file contents leave the local machine and may

be retained under Telegram's policies.

  • This skill cannot verify that a chat ID belongs to the intended recipient; confirm the target

before every new destination or automation.

  • Bot tokens grant control of the bot. Store them only in a protected local secret store or

mode-600 configuration file. The script supplies token-bearing API URLs to curl through

stdin rather than process arguments; rotate a token if exposure is suspected.

  • Do not use the examples to create unattended notifications or approval flows without the

user's explicit, current authorization.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

同名技能的其他版本

有 2 个不同仓库或目录里都有叫 telegram-bot-messaging 的技能。它们内容并不相同,别混用: