Is acastellana/telebiz-mcp-skill safe?
Yes. acastellana/telebiz-mcp-skill is safe to install. Oathe's behavioral security audit gave the telebiz-mcp-skill skill by acastellana a trust score of 94/100 with 3 findings, none critical or high.
https://github.com/openclaw/skills/tree/main/skills/acastellana/telebiz-mcp-skill
Is acastellana/telebiz-mcp-skill safe to install?
This is a legitimate Telegram MCP integration skill that provides chat management, messaging, and search capabilities via a browser-based Telegram client. The skill communicates only with local WebSocket/HTTP endpoints (ports 9716/9718) and requires user authentication through the external telebiz.io service. No prompt injection, data exfiltration, or malicious code patterns were detected. The skill includes appropriate security documentation and rate limiting.
What security issues were found in acastellana/telebiz-mcp-skill?
Category Scores
Findings (3)
LOW HTTP server allows all CORS origins 5 ▶
The HTTP server (http-server.js) sets Access-Control-Allow-Origin: '*', which allows any origin to make requests. This is standard for MCP servers but worth noting.
LOW Local state file storage 5 ▶
The monitor and health scripts store state in ~/.telebiz-mcp-state.json. This is expected behavior for state tracking but stores local process information.
INFO Security depends on external telebiz.io service 0 ▶
The skill relies on telebiz.io browser client running in user's browser. Security depends on that external service's integrity. This is documented in SKILL.md.
Should I install acastellana/telebiz-mcp-skill?
Oathe's verdict for acastellana/telebiz-mcp-skill is SAFE with a trust score of 94/100. Recommendation: Install.