which Telegram API each surface speaks, and what each one costs
telegram-dev
Telegram, split by the API each surface actually speaks, in three skills. telegram-bots covers the official HTTP Bot API: update_id as the only idempotency key an update carries, the allowed_updates default that subscribes you to everything except chat_member and the two reaction types while returning ok, the webhook secret header that is the real check, rate limits as a design constraint rather than an error path, and Telegram Stars with a ten-second pre-checkout window and the grant that belongs to successful_payment. telegram-userbots covers MTProto and Telethon: the session file as a credential equal to the password, FloodWaitError as the API telling you exactly how long to wait, pinning across minor releases that move session and entity-cache behaviour, and the account-ban risk a bot token does not carry — opening with whether a user account is needed at all. telegram-miniapps covers the web layer, whose entire security model is one signed query string: verifying initData server-side, the auth_date window, the Ed25519 path for a third party, and the SDK package whose name moved. Both the verifier and the delivery invariants ship as runnable fixtures with their mutants.
Install this pack on its own, or use it with the ssheleg harness.
What it ships
Each name below is an entry point an agent can be routed to.
Shape: static. Three fixed surfaces with fixed seams; the only branch is which of the three a task is on, and the first table in each SKILL.md decides that before any code.
telegram-bots
Use when building, adding or auditing a Telegram bot (Telegram, Telegram) on the official HTTP Bot API: receiving updates by polling or webhook, deduplicating them, keyboards and inline mode, Telegram Stars payments, files, rate limits, and the seam where an update becomes a row in your own database. Covers the pinned API version, update_id as the only idempotency key, the allowed_updates default that drops three update types in silence, the webhook secret header, the ten-second pre-checkout window, XTR and refunds, the 20MB download ceiling, and what a bot cannot do at all. Not for user accounts or reading history a bot cannot see (telegram-userbots), and not for the web layer (telegram-miniapps).
telegram-userbots
Use when a Telegram job needs a user account rather than a bot token — reading history a bot cannot see, acting as a person, exporting at scale, or downloading past the Bot API ceiling — with Telethon or another MTProto client. Covers the decision of whether a user account is needed at all, the session file as a credential equal to the password, api_id and api_hash, FloodWaitError as the API working rather than failing, entity resolution and its cache, pinning across minor releases that move session and cache behaviour, two-factor login, takeout for bulk export, and the account-ban risk a bot token does not carry. Not for ordinary bots (telegram-bots) or the web layer (telegram-miniapps).
telegram-miniapps
Use when building or auditing a Telegram Mini App — a web page opened inside Telegram — where the whole security model is one signed blob. Covers verifying initData on the server with HMAC-SHA256 and the key derivation, why initDataUnsafe is named that, the auth_date freshness window, the Ed25519 signature path for a third party with no bot token, session exchange, sending results back to the bot with sendData and answerWebAppQuery, Stars payments inside the app, the viewport and safe-area fields a real device needs, and the SDK package whose name moved. Not for the bot behind it (telegram-bots) or user accounts (telegram-userbots).
Install just this one
Every pack installs standalone. The whole family is one command.
npx skills add ssheleg/telegram-dev
claude plugin marketplace add ssheleg/telegram-dev && claude plugin install telegram-dev@telegram-dev
When the agent reaches for it
These are the rules the family writes into your agent's own instruction file — verbatim. Each one states the rule, the boundary in both directions, and the phrase that declines it.
/telegram-dev — which Telegram API a surface speaks, and what it costs
- when: the thing being built lives inside Telegram
- decline it: no telegram
If telegram-dev is installed, Telegram surfaces go through it — Bot API bots, MTProto accounts, Mini Apps. update_id is an update's only idempotency key; a session file is a logged-in person, revocable and bannable. For Mini Apps, validate raw initData on the backend; never trust initDataUnsafe.
The boundary — "Telegram is the platform, not the transport." NOT through it: a one-call bot alert to yourself, bot behavior (super-ux), Mini App look (sheleg-design), card charges (sheleg-dev).
Refusal phrase: "no telegram" or «без телеграма».
Among the routers: sheleg-dev owns card rails; telegram-dev owns Stars, bot tokens, accounts and their risks.
The rest of the family
super-ux v0.59.1
Scenario-driven UI development: a versioned design chain in docs/ux/ — the product vision, personas and jobs, user flows and the paid-acquisition funnel among them, a screens-and-states map with Figma frames…
task-pipeline v1.90.2
Full-cycle delivery orchestrator: an intake grill turns the request into a complete brief, then ten gated stages carry it from docs to acceptance, refusing to advance until each gate passes.
agent-sync v1.21.5
Coordination plane for concurrent agents: leases with a TTL so two agents cannot claim the same work, race-free id reservation, a run journal and a generated board, over a pluggable knowledge cloud.
make-skill v0.29.2
A skill that builds skills: create, retrofit, audit and publish agent skills and Claude Code plugins
sheleg-design v1.64.0
The taste layer: cinematic scroll-driven landing pages (one scroll clock, motion that degrades to calm, WebGL particle formations), product-UI style packs with a ready token layer each, and the Figma border
seo-aeo-audit v0.26.3
Evidence-first website audit for search and answer engines: ten tracks from crawl access to AI citation mechanics, every finding backed by an observation and every recommendation tiered, ending in…
sheleg-dev v0.13.2
The integration layer a product reaches once it has users: Stripe subscription billing reconciled into your own database
agent-stack v0.25.5
Production patterns for AI agent systems, in four skills. The orchestrator: tool-calling loops that survive context pressure, pipelines with human checkpoints and resume, provider routing with fallback…
xr-dev v0.3.2
Quest product delivery from platform choice to launch and operation, with stage owners, evidence gates and next actions.
web3d-dev v0.1.2
Realtime 3D on the web with three.js and React Three Fiber, in three skills split by the question. web3d-runtime owns how the scene runs