telegram-account-orchestrator (soulknight666/telegram-account-orchestrator) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. No publisher has claimed this listing.
MCP server for self-hosted Telegram multi-account management, enabling encrypted session storage, health checks, batch operations, device-session management, and automation through AI agents.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
soulknight666
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
TAM_API_IDTELEGRAM_APP_IDTAM_API_HASHTELEGRAM_APP_HASHTAM_TOAPI_BASE转 API 相关环境变量:(优先)、DM、SERVER_IP/API_PORT。DM转 API 相关环境变量:TAM_TOAPI_BASE(优先)、、SERVER_IP/API_PORT。SERVER_IP转 API 相关环境变量:TAM_TOAPI_BASE(优先)、DM、/API_PORT。API_PORT转 API 相关环境变量:TAM_TOAPI_BASE(优先)、DM、SERVER_IP/。TAM_DATA_DIRNO_COLORWT_SESSIONTERM_PROGRAMTAM_RESTARTED_AT_TAM_DUR_PROBETAM_ENV_FILETAM_BOT_TOKEN选了机器人但还没有 Token:会提示填一次 @BotFather 的 (可回车跳过,稍后写 .env)。BOT_TOKENTAM_BOT_ADMIN_IDADMIN_IDSTART_JOIN_USERNAMEOKPAY_ID填了 / OKPAY_TOKEN / OKPAY_COST 才会开付费门槛:下单后每 5 秒轮询,5 分钟不付自动关单,OKPAY_TOKEN填了 OKPAY_ID / / OKPAY_COST 才会开付费门槛:下单后每 5 秒轮询,5 分钟不付自动关单,OKPAY_PAYEDOKPAY_COST留空就是不收费,任何人进来直接是 VIP(自用场景默认这样)。TAM_PORTTAM_MASTER_KEYpython -m tam.cli init-key # 生成 ,写入 .envTAM_WEB_TOKEN所有 /api/ 需 Authorization: Bearer <>。若向导里选了“本机免令牌”(TAM_NO_AUTH=1 且 TAM_WEB_TOKEN 为空),则不需要任何头部,直接访问即可。TAM_DEFAULT_PROXYTAM_READONLY1 或使用 TAM_READONLY_TOKEN 时,写入类工具从清单中消失并被拒绝——推荐给 Agent 单独发只读令牌。TAM_DRY_RUN1 全局干跑;TAM_PEER_ALLOWLIST 限定可发送对象。TAM_READONLY_TOKENTAM_READONLY=1 或使用 时,写入类工具从清单中消失并被拒绝——推荐给 Agent 单独发只读令牌。TAM_PEER_ALLOWLISTTAM_DRY_RUN=1 全局干跑; 限定可发送对象。TAM_NO_AUTH所有 /api/ 需 Authorization: Bearer <TAM_WEB_TOKEN>。若向导里选了“本机免令牌”(=1 且 TAM_WEB_TOKEN 为空),则不需要任何头部,直接访问即可。TAM_BATCH_CONCURRENCY3 工具箱、批量任务同时开几个号;调大易触频控TAM_DEPLOYpython -m tam.cli run # 读 .env 里的 / TAM_FRONTENDTAM_FRONTENDpython -m tam.cli run # 读 .env 里的 TAM_DEPLOY /TAM_NO_MENUTAM_HOSTTAM_PROXY_FILETAM_WORKERS4 ZIP 拆包 / 合并 / 注册时间分类的并发度,上限 32TAM_KICK_RETRY1h 失败后的重试间隔,支持秒/分/时写法:45s、10m、2h、1h30m,纯数字按秒,最小 10 秒。UNPACK_TOOL_BACKMK_TIMEMK_LIST_TIMEPREVENT_RECOVERY_BACKFORMAT_CONVERT_BACKPASSKEY_BACKOKPAY_RETURN_URLCLEAN_ACCOUNT_BACKCHECK_BAN_BACKSHAIHUO_BACKCHECK_MATERIAL_BACKTEST_BIDIRECTIONAL_BACKDESTROY_BACKCHANGE_2FA_BACKPRIVACY_CONFIG_BACKCONVERT_API_BACKTAM_MAX_EXTRACT_MB512 解压后总大小上限,防 zip 炸弹Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
73/73 tools missing one or more hints — _list_settings (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); _update_settings (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); _list_accounts (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +70 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Destructive tools are labelled
2 tools perform destructive updates without destructiveHint — _zip_merge deletes at line 703 (shutil.rmtree(src, ignore_errors=True)); _zip_cleanup deletes at line 759 (shutil.rmtree(d, ignore_errors=True))
Add destructiveHint:true to any tool whose handler calls .delete(), .upsert(), .update(), unlink, rm, DELETE, DROP, REPLACE INTO, or any operation that overwrites existing data.
Tool inputs are validated
70/73 tool handlers declare input schemas (96%)
Declare an inputSchema with zod/joi/yup on every tool definition.
Tool handlers catch errors
Only 7/73 tool handlers wrap calls in try/catch (10%)
Wrap each tool handler body in try/catch and return a structured error response.
Tests exist
No test files found
Add tests that exercise each declared tool.
Shell command execution
2 child_process calls — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/soulknight666-telegram-account-orchestrator-1b0vvc)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check