Back to skill

Security audit

WhatsApp Outreach Platform — AI Leads, Bulk Messaging, Reviews & CRM Pipeline

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only WhatsApp automation skill is purpose-related, but it documents powerful messaging, export, billing, and automation capabilities with scope and confirmation gaps that should be reviewed before use.

Install only if you are comfortable giving an agent access to a WhatsApp automation service that can send messages, create schedules, manage contacts/groups, export personal data, upload business documents, and affect billing. Prefer OAuth or short-lived, least-privilege API keys; avoid paste-in config or shell-history secrets; do not use the read-only onboarding workflow with send/manage scopes; enable approval mode and whitelisting before any bulk, scheduled, AI-generated, or channel outbound messaging.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
moltflow-onboarding/SKILL.md:38
Finding

Read-Only Onboarding Workflow Requires Write-Capable API Key Scopes

Content
View full analysis

Vulnerability Details

File Location: moltflow-onboarding/SKILL.md, lines 38-43
Vulnerability Type: Excessive privileges and violation of least privilege
Risk Level: High

Vulnerable code:

markdown
## Required API Key Scopes

| Scope | Access |
|-------|--------|
| `sessions` | `manage` |
| `messages` | `send` |

The requested permissions conflict with the module's explicitly read-only behavior:

markdown
## Step 1: Fetch Account Data (Read-Only)

Gather data from these read-only endpoints. All are `GET` requests authenticated via `X-API-Key: $MOLTFLOW_API_KEY` header. Base URL: `https://apiv2.waiflow.app/api/v2`.

| Endpoint | Data | Full Docs |
|----------|------|-----------|
| `GET /users/me` | Account & plan | moltflow-admin SKILL.md |
| `GET /sessions` | WhatsApp sessions | moltflow SKILL.md |
| `GET /groups` | Monitored groups | moltflow SKILL.md |
| `GET /custom-groups` | Custom groups | moltflow-outreach SKILL.md |
| `GET /webhooks` | Webhooks | moltflow SKILL.md |
| `GET /reviews/collectors` | Review collectors | moltflow-reviews SKILL.md |
| `GET /tenant/settings` | Tenant settings | moltflow-admin SKILL.md |
| `GET /scheduled-messages` | Scheduled messages | moltflow-outreach SKILL.md |
| `GET /usage/current` | Usage stats | moltflow-admin SKILL.md |
| `GET /leads` | Existing leads | moltflow-leads SKILL.md |
| `GET /messages/chats/{session_id}` | Chats (per session) | moltflow SKILL.md |

Technical Analysis

The onboarding Skill declares itself a read-only account-health and growth-report workflow. Its documented operations use HTTP GET requests to retrieve account metadata, usage, sessions, leads, and chat summaries. Nevertheless, it asks users to grant sessions:manage and messages:send capabilities.

sessions:manage can authorize state-changing session operations, while messages:send permits outbound WhatsApp communication. Neither p ...[truncated 1416 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace sessions:manage with sessions:read.
  • Replace messages:send with messages:read.
  • Document every additional read scope needed for the listed endpoints, such as read-only scopes for groups, custom groups, webhooks, reviews, settings, schedules, usage, and leads.
  • Provide a dedicated onboarding or account-health scope that cannot invoke any state-changing endpoint.
  • Reject write-capable credentials when executing the read-only onboarding workflow, or prominently warn the user and request a replacement read-only key.
  • Add automated tests verifying that all onboarding requests use safe HTTP methods and that its key cannot send messages, alter sessions, update settings, or modify resources.
  • Use a short-lived key limited to the current tenant and rotate or revoke it after the report is generated.

T09 · Insecure Skill Coding Practices

Warning
Location
integrations.md:39
Finding

Manual MCP Authentication Exposes API Keys Through Persistent Configuration and Command-Line History

Content
View full analysis

Vulnerability Details

File Location: integrations.md, lines 39-51 and 94-98
Vulnerability Type: Insecure credential storage and command-line secret exposure
Risk Level: Medium

Vulnerable configuration example:

markdown
### Option B: API Key (Manual)

If you prefer explicit key management:

```json
{
  "mcpServers": {
    "moltflow": {
      "url": "https://apiv2.waiflow.app/mcp",
      "headers": {
        "X-API-Key": "YOUR_API_KEY_HERE"
      }
    }
  }
}
text

**Vulnerable command-line example:**

```markdown
For manual auth with an API key:

```bash
claude mcp add moltflow --transport http --url https://apiv2.waiflow.app/mcp --header "X-API-Key: YOUR_API_KEY_HERE"
text

### Technical Analysis

The documentation instructs users to replace `YOUR_API_KEY_HERE` with a real secret in a persistent MCP configuration or a shell command.

A key stored directly in `claude_desktop_config.json` may be exposed through file backups, synchronization systems, diagnostic bundles, accidental source-control commits, or overly broad filesystem permissions. Supplying the key as a command-line argument can additionally disclose it through shell history, terminal logging, process inspection, or audit tooling.

This contradicts the same file's recommendation to store API keys in environment variables rather than shared configuration files. The risk increases when the key includes messaging, group-management, outreach, or administrative scopes.

### Attack Path

1. The user replaces the placeholder with a live MoltFlow API key.
2. The key is written into an MCP configuration file or retained in shell history.
3. Another local user, process, backup operator, support bundle, repository reader, or endpoint-monitoring product obtains the stored command or configuration.
4. The attacker extracts the `X-API-Key` value.
5. The attacker authenticates directly to the MoltFlow MCP or RES
...[truncated 514 chars]
Remediation
View remediation

Remediation Suggestions

  • Retain OAuth 2.1 with PKCE as the default and strongly preferred authentication method.
  • Remove examples that place live secrets directly in JSON configuration or command-line arguments.
  • Use a protected environment-variable reference, operating-system credential store, or MCP client's native secret-storage mechanism.
  • If the client cannot reference a secret securely, clearly document the residual risk and require restrictive file permissions.
  • Warn users that command-line secrets may appear in shell history and process listings.
  • Recommend short-lived, minimum-scope API keys with explicit expiration dates.
  • Add instructions for immediate rotation if a key is committed, logged, copied into support output, or otherwise exposed.
  • Ensure generated configuration files containing credentials are excluded from source control and backups where practical.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:463
Finding

Configurable API Origin Can Redirect Authenticated Requests to an Untrusted Server

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 463-472
Vulnerability Type: Unsafe configurable network destination for authenticated traffic
Risk Level: Medium

Vulnerable code:

markdown
**Env vars:**
- `MOLTFLOW_API_KEY` (required) — create a
  minimum-scoped key from
  [your dashboard](https://molt.waiflow.app).
  Use the narrowest scope preset that covers
  your workflow. Rotate keys regularly.
- `MOLTFLOW_API_URL` (optional) — defaults
  to `https://apiv2.waiflow.app`

**Authentication:**
`X-API-Key: $MOLTFLOW_API_KEY` header

Technical Analysis

The Skill documents an environment-controlled API URL while separately directing clients to attach MOLTFLOW_API_KEY to requests. It does not specify an HTTPS-only requirement, trusted-host allowlist, certificate policy, or rule preventing credentials from being forwarded when the origin differs from apiv2.waiflow.app.

An environment variable can be inherited from shell profiles, CI/CD configuration, container definitions, process supervisors, or attacker-controlled launch scripts. If client implementations combine the documented URL override with the documented authentication header, a modified environment can redirect authenticated requests to a hostile server.

This also conflicts with the root Skill's claim that API calls are made only to apiv2.waiflow.app.

Attack Path

  1. An attacker gains the ability to influence the process environment, deployment configuration, shell profile, container environment, or CI variables.
  2. The attacker sets MOLTFLOW_API_URL to an attacker-controlled endpoint.
  3. The user or agent launches the Skill without noticing the overridden origin.
  4. The client constructs requests using the altered base URL and attaches X-API-Key: $MOLTFLOW_API_KEY.
  5. The attacker's server receives the API key and any request data sent by the workflow.
  6. The attacker reuses the captured key against ...[truncated 551 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove MOLTFLOW_API_URL if alternate deployments are not a necessary supported feature.
  • Otherwise, enforce HTTPS and validate the destination against an explicit trusted-host allowlist.
  • Never attach MOLTFLOW_API_KEY when the effective origin differs from the approved MoltFlow API origin.
  • Require explicit, visible user confirmation before using a custom API endpoint.
  • Reject URLs containing embedded credentials, nonstandard schemes, local addresses, link-local addresses, or cloud metadata endpoints.
  • Do not follow cross-origin redirects while retaining authentication headers.
  • Log the effective hostname without logging credentials so users can verify where requests are sent.
  • Use separate credentials for self-hosted or test endpoints rather than reusing production MoltFlow keys.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:354
Finding

Unpinned Third-Party Python SDK Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 354
Vulnerability Type: Unpinned external dependency installation
Risk Level: Medium

Vulnerable code:

markdown
- Python SDK: `pip install moltflow` ([GitHub](https://github.com/moltflow/moltflow-python))

Technical Analysis

The recommended command installs whichever moltflow package version is currently selected by the user's configured Python package index. It does not pin an audited version, verify a cryptographic hash, or bind the package-index artifact to a reviewed source commit.

Package-index content is mutable from the perspective of this static audit. A compromised maintainer account, malicious future release, index substitution, or dependency compromise could cause users to install code different from the documentation that was reviewed. Python packages may execute installation or runtime code with the invoking user's privileges.

The project itself does not bundle or automatically execute this SDK; exploitation requires a user to follow the external installation recommendation.

Attack Path

  1. A user follows the documentation and runs pip install moltflow.
  2. pip resolves the latest compatible package from the configured package index.
  3. The resolved package or one of its transitive dependencies has been compromised or replaced by a malicious release.
  4. Installation or subsequent import executes attacker-controlled Python code.
  5. The malicious code accesses resources available to the user, potentially including environment variables such as MOLTFLOW_API_KEY.
  6. The attacker uses stolen credentials or local execution privileges for further compromise.

Impact Assessment

Malicious package code would run with the privileges of the user or environment invoking pip. It could read local files and environment variables, modify user-level files, access network resources, or steal MoltFlow credentials.

The ult ...[truncated 187 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the SDK to a specific reviewed version, for example using an exact == constraint.
  • Publish and document SHA-256 hashes and recommend installation with hash verification.
  • Bind the documented release to a signed source tag or immutable commit.
  • State the authoritative package index and verify package ownership.
  • Pin and audit transitive dependencies through a lock file or constraints file.
  • Recommend installation in an isolated virtual environment using a nonprivileged account.
  • Encourage users to inspect package metadata and source before installation.
  • Add automated dependency scanning and release-signing controls to the SDK publication process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (48)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · moltflow-admin/SKILL.md (reported line 71)May include surrounding context.

md
| Method | Endpoint | Description |
|--------|----------|-------------|
| POST | `/auth/login` | Login with email/password |
| POST | `/auth/refresh` | Refresh access token |
| GET | `/auth/me` | Get current user profile |
| POST | `/auth/logout` | Invalidate session |
| POST | `/auth/forgot-password` | Request password reset email |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · moltflow-admin/SKILL.md (reported line 343)May include surrounding context.

md
## Tips

- **API key security**: The raw key is only shown once at creation. Store it in a secrets manager.
- **Token refresh**: Access tokens expire in 30 minutes. Use the refresh endpoint to get new ones without re-authenticating.
- **Magic links**: For passwordless login, use `magic-link/request` then `magic-link/verify`.
- **Plan limits**: Use `GET /billing/subscription` to check remaining quotas before making API calls.
- **Scoped keys**: Always use the minimum scopes needed for your workflow.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file highlights capabilities such as scheduled messages, bulk messaging, custom group building, contact export, and knowledge-base document upload, all of which can affect user data, privacy, or outbound communications. Under the markdown criteria for SQP-2, these behaviors should be accompanied by warnings or constraints, but the referenced lines present them as features only.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill presents a 'read-only' account scan with 'no data modified,' but the broader document describes write-capable automation such as creating leads, groups, scheduled sends, and status changes. Even if the specific scan endpoint is read-only, this messaging can mislead users and downstream agents about the overall capability and safety boundaries of the skill, increasing the chance of unintended state-changing actions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

'Auto-approve positives' describes autonomous content selection/publication behavior based on sentiment scoring. In a messaging and review-management context, this can create integrity and compliance risks by publishing or promoting content without human verification, especially if the classifier is wrong or manipulated.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
**"Collect customer reviews after every reservation and export the best ones"**

Sentiment-scored review collection, auto-approve positives, export as HTML for your website.

**"Send a weekly campaign performance report to my team's WhatsApp group every Monday"**

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

Get campaign analytics — delivery rates, funnel, timing

bash
curl -H "X-API-Key: $MOLTFLOW_API_KEY" \
  "https://apiv2.waiflow.app/api/v2/analytics/campaigns/{job_id}"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 404)May include surrounding context.

md
| Style Clone | Matches your writing tone |
| RAG | PDF/TXT, semantic search |
| Voice | Whisper transcription |
| Reviews | Sentiment, auto-approve |
| Anti-Spam | Rate limits, typing sim |
| Safeguards | Block PII, injections |
| Webhooks | HMAC signed, 10+ events |

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file claims 'All actions require user confirmation,' yet elsewhere advertises recurring schedules, auto-replies, monitoring triggers, and other post-setup autonomous behavior. This inconsistency can cause users or agent frameworks to overtrust the skill and enable workflows that continue acting without per-action review.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 434)May include surrounding context.

md
## What This Skill Reads, Writes & Never Does

**Documentation and API reference.** Nothing is
auto-installed or auto-executed. No scripts or
executables are bundled in this package.
All actions require user confirmation.

Scope Creep

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation states the required API key scope is only a2a, yet the listed capabilities include sending WhatsApp messages, group operations, and webhook management. This scope/capability ambiguity can lead consumers to overtrust a key or misunderstand what authenticated access permits, increasing the risk of unintended privileged actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The A2A skill documents methods that trigger direct real-world WhatsApp actions such as sending messages and managing groups, which expands from passive agent discovery/coordination into externally impactful communications. In an agent ecosystem, that mismatch increases the chance an integrating agent invokes high-impact actions without adequate user confirmation or scope separation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes message sending and group-management actions that have immediate effects on external WhatsApp users, but it does not prominently warn operators that these are real-world outbound actions. In agent-driven environments this omission can cause accidental spam, unauthorized outreach, or unintended contact with third parties.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · moltflow-a2a/SKILL.md (reported line 383)May include surrounding context.

Discover the MoltFlow agent

bash
curl https://apiv2.waiflow.app/.well-known/agent.json

Send a message via A2A

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documents credential-based login with email/password but does not include an explicit warning that the user is about to provide secrets to a third-party service. In an agent context, this can normalize prompting for credentials and increase the chance of users exposing passwords or refresh tokens without clear consent boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The billing section includes charge-creating and subscription-altering actions such as checkout, portal access, and cancellation without a clear warning that these operations may create charges or modify billing state. In an agent workflow, this raises the risk of accidental purchases, unwanted plan changes, or cancellations initiated without sufficiently informed user confirmation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · moltflow-admin/SKILL.md (reported line 243)May include surrounding context.

Get Tenant Settings

bash
curl https://apiv2.waiflow.app/tenant/settings \
  -H "X-API-Key: $MOLTFLOW_API_KEY"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The voice transcription feature processes WhatsApp voice messages and stores searchable transcript text, which may include sensitive personal, customer, or patient information. Although the feature is described functionally, there is no user-facing warning about consent, privacy implications, or handling of sensitive audio/transcript data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file documents a feature that uploads and indexes business documents for AI retrieval, which can expose sensitive or regulated content to downstream AI processing. The section describes file types and API behavior but does not warn users to avoid uploading confidential, personal, or regulated data unless they have appropriate authorization and safeguards in place.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · moltflow-ai/SKILL.md (reported line 410)May include surrounding context.

Upload a knowledge base document

bash
curl -X POST https://apiv2.waiflow.app/api/v2/ai/knowledge/ingest \
  -H "X-API-Key: $MOLTFLOW_API_KEY" \
  -F "file=@product-catalog.pdf"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow encourages bulk add-to-group and follow-up outreach without a clear warning that these actions can result in mass user-visible contact and possible spam or consent violations. Although the reciprocity check is mentioned, it is advisory rather than enforced, so users may still operationalize large-scale unsolicited outreach directly from detected group activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents bulk lead export to CSV/JSON containing phone numbers, names, statuses, and group-derived lead metadata, but provides no privacy, consent, retention, or secure-handling guidance. This increases the risk that operators will exfiltrate or mishandle personal data outside the platform, especially because exports are positioned as a normal workflow for CRM import.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · moltflow-leads/SKILL.md (reported line 254)May include surrounding context.

bash
# 1. List new leads from a specific group
curl "https://apiv2.waiflow.app/api/v2/leads?status=new&source_group_id=group-uuid" \
  -H "X-API-Key: $MOLTFLOW_API_KEY"

# 2. Check reciprocity before reaching out

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad, everyday requests such as 'help me get started' and 'give me my morning report,' which can cause the skill to activate in contexts where the user did not intend account-level data retrieval. In this skill's context, accidental invocation could expose account metadata, usage, chats, and group information to the model flow unnecessarily, increasing privacy and overcollection risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill repeatedly claims to be strictly read-only, but its documented required scopes include messages: send, which grants write capability well beyond what the workflow needs. This creates a dangerous mismatch between user/operator expectations and actual authority: if the skill, a linked module, or an upstream prompt path is abused, the exposed credential could be used to send WhatsApp messages despite the 'read-only' framing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill supports importing WhatsApp group members, exporting contact data, and bulk messaging without any clear guardrails around consent, lawful basis, privacy, or recipient-data handling. In context, this can facilitate scraping and mass outreach to people who did not opt in, creating privacy, compliance, and abuse risks at scale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.