Skip to content

Security: etinpres/herdr-telegram-remote

SECURITY.md

Security Policy

Herdr Telegram Remote can inject text and key events into coding-agent panes. Treat the Telegram bot token and every authorized Telegram account as having the same practical access as the local user running Codex or Claude Code.

Supported versions

Security fixes are provided for the latest tagged beta/release only.

Report a vulnerability

Use GitHub's private vulnerability reporting for this repository. Do not open a public issue containing bot tokens, chat IDs, user IDs, pane transcripts, screenshots, filesystem paths, or agent session IDs.

Include the affected version, operating system, Herdr version, reproduction steps, and impact. Replace all credentials and personal identifiers with placeholders.

If a bot token leaks

  1. Open @BotFather in Telegram.
  2. Revoke/regenerate the affected bot token immediately.
  3. Replace TELEGRAM_BOT_TOKEN in .env and keep the file mode at 600.
  4. Restart the launchd/systemd service.
  5. Review ALLOWED_USER_IDS, TELEGRAM_CHAT_ID, local logs, and recent agent activity before resuming remote control.

Security boundaries

  • TELEGRAM_CHAT_ID and ALLOWED_USER_IDS are both enforced.
  • The bot does not create an authentication boundary inside Codex or Claude Code. The selected agent still has whatever local permissions it was started with.
  • Natural-language prompts can request destructive work even when a slash command is not in the explicit dangerous-command list.
  • /restart x starts Claude Code with permission bypass and therefore requires a separate confirmation token.
  • Screenshots and uploaded images may contain secrets. Keep the Telegram group private and review PRIVACY.md.

This is an independent community project and is not affiliated with Herdr, OpenAI, Anthropic, or Telegram.

There aren't any published security advisories