Chapter 23 · CLI
Channels: Telegram, Discord, iMessage and trust boundaries
Channels push external events into a running session: a Telegram, Discord or iMessage message can reach the session and influence it. Powerful, but it demands clear trust boundaries.
Video
Steps
- Understand what a channel does: an external event source feeding the session, not necessarily a full two-way communication line.
- Define which sources may inject events, and treat inbound content as untrusted data even when it looks familiar.
- Limit what the session may do following an event: read and respond, not automatic destructive actions.
- Test the integration in a sandbox before connecting a real channel, and document the trust boundaries you chose.
Common pitfall: Content arriving from an external channel can try to order the session into malicious actions; an event is input to weigh, not a command to execute.
Hands-on exercise: Read the official channels page and record which channels are supported and what permissions each requires. Decide which boundaries you would set.
Filmed demo · Video is added in the media phase
Recap
Comprehension check
How should content from an external channel be treated?
Recap
- Channels feed events into a running session
- External input is not a command
- Limit actions triggered by events