Back to skill

Security audit

GOWA - WhatsApp Automation

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent WhatsApp automation guide, but it recommends a powerful local REST control API for production without requiring authentication or clear confirmations for high-impact actions.

Review before installing or using. Only run the REST API on a tightly controlled host, enable authentication, avoid exposing port 3000, and require explicit confirmation before sending messages, using @everyone or ghost mentions, downloading private media, logging out devices, or changing group membership/admin state.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/api-endpoints.md:3
Finding

Unauthenticated High-Impact WhatsApp Control API Recommended for Production Use

Content
View full analysis

Vulnerability Details

File Location: references/api-endpoints.md:3-8 and SKILL.md:28-38
Vulnerability Type: Unauthenticated access to a sensitive local control API
Risk Level: Medium

Vulnerable code segment (references/api-endpoints.md:3-8):

markdown
Base URL: `http://localhost:3000` (default)

## Authentication
- No authentication required by default
- Optional Basic Auth (if GOWA started with `--basic-auth=user:password`)
  - Header: `Authorization: Basic <base64(user:password)>`

Related production guidance (SKILL.md:28-38):

markdown
## Production Setup

**GOWA runs in REST mode:**
- Base URL: `http://localhost:3000`
- GOWA auto-connects to the device stored in the database — no `X-Device-Id` header needed for single-device setups.

**⚠️ Important:** Use REST API (port 3000) only. Do NOT use MCP mode - all schedulers and automation depend on REST.

Technical Analysis

The Skill recommends using the REST service in production while documenting that authentication is disabled by default. The service controls a linked WhatsApp account and exposes sensitive and destructive operations, including reading chats and contacts, downloading message media, sending messages, changing group membership and administrator roles, logging out devices, and obtaining login information.

Binding the service to localhost can reduce direct network exposure, but it is not an authentication boundary. Other local processes may access the API, and applications vulnerable to server-side request forgery may be able to send requests to loopback services. Exposure may also increase if the service is inadvertently bound to a non-loopback interface, published from a container, or made reachable through a reverse proxy.

Because Basic Authentication is merely optional, following the documented default configuration can leave all API capabilities available without proving the caller's identit ...[truncated 1841 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require authentication in all documented production configurations rather than presenting it as optional.
  2. Generate a strong, unique credential for the service and store it in a protected secret store or environment variable rather than source files or shell history.
  3. Bind the service explicitly to the loopback interface when remote access is unnecessary; do not rely only on a port number or hostname convention.
  4. Apply host firewall rules so that only authorized local users or trusted management systems can reach port 3000.
  5. If remote access is required, place the service behind an authenticated TLS reverse proxy, restrict source networks, and avoid directly publishing the API port.
  6. Isolate the service in a dedicated operating-system account or container with narrowly scoped network access and protected session data.
  7. Add authorization controls for high-impact operations, particularly device logout, media download, message sending, and group administration.
  8. Apply request rate limits, audit logging, and alerts for unusual message volume, mass mentions, account changes, or group administration activity.
  9. Validate Origin and other relevant request context where browser access is supported, and use appropriate anti-CSRF protections for state-changing browser requests.
  10. Update the Skill documentation so every production example includes authenticated requests and clearly warns that unauthenticated mode is suitable only for tightly isolated development environments.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The documented DELETE /devices/:device_id endpoint is a high-risk parameterized destructive action: if an agent is allowed to pass arbitrary device_id values, it could remove the wrong device or be manipulated into disconnecting service. Because the API is documented as unauthenticated by default and defaults to implicit device selection in some cases, misuse of device-scoped operations is especially dangerous in multi-device environments.

Content

Scanner excerpt · references/api-endpoints.md (reported line 23)May include surrounding context.

md
- `GET /devices` - List all registered devices
- `POST /devices` - Add new device
- `GET /devices/:device_id` - Get device info
- `DELETE /devices/:device_id` - Remove device
- `GET /devices/:device_id/login` - Login with QR code
- `POST /devices/:device_id/login/code` - Login with pairing code
- `POST /devices/:device_id/logout` - Logout device

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description advertises automation for sending messages, media, contacts, and location data through a WhatsApp REST API but does not warn that these actions transmit user-provided content to an external messaging channel tied to a real account. That omission can cause users or downstream agents to trigger privacy-sensitive or irreversible outbound actions without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This example performs an outbound POST to a local REST service that in turn sends a real WhatsApp message to a group, including a ghost mention feature that can notify all members. Although the endpoint is localhost, the effective behavior is external transmission to third parties and could be abused for spam, harassment, or accidental disclosure if invoked without safeguards.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

Ghost Mention (mention all without @)

bash
curl -X POST http://localhost:3000/send/message \
  -H "Content-Type: application/json" \
  -d '{
    "phone": "120363040656010581@g.us",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents destructive operations such as removing participants, promoting/demoting admins, leaving groups, revoking messages, editing messages, and marking content as read without any cautionary guidance or confirmation requirements. In an automation context, these actions can alter group state, destroy evidence, or create user-visible side effects that are difficult to undo.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This scheduler example automates sending a WhatsApp group message with ghost mentions, which increases the risk of repetitive unsolicited messaging and broad user notification at scale. In context, the skill is specifically designed for personal automation, so unattended execution makes accidental spam or misuse more likely despite the example appearing operationally legitimate.

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

Example for schedulers:

bash
curl -s -X POST http://localhost:3000/send/message \
  -H 'Content-Type: application/json' \
  -d '{"phone": "120363040656010581@g.us", "message": "Reminder text", "mentions": ["@everyone"]}' | jq .

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The reference documents numerous destructive and privacy-impacting operations such as device removal, logout, message deletion, media download, contact/group enumeration, participant export, and group administration without any safety guidance, confirmation requirements, or warnings about misuse. In a personal automation skill that interfaces with WhatsApp, this increases the chance that an agent or user will invoke high-risk actions casually, leading to privacy loss, account disruption, or unwanted messaging at scale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.