Back to skill

Security audit

WhatsApp & Calls

Security checks across malware telemetry and agentic risk

Overview

This skill openly connects OpenClaw to 2Chat so an authorized account can manage WhatsApp, SMS, contacts, statuses, and call data.

Install only for a 2Chat account and WhatsApp/SMS channels you are authorized to use. Treat it as sensitive third-party account access because the agent can read and send messages, manage contacts and groups, publish statuses, and view call records through 2Chat.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README states that the skill can send and read WhatsApp messages, send SMS, manage contacts and groups, publish statuses, browse catalogs, and pull voice call records. For a markdown file, these are user-data and privacy-impacting behaviors, but the description does not include any caution or disclosure about data access, transmission to the remote 2Chat service, or the need to use it only with authorized accounts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.