other
- Location
SKILL.md:168- Finding
Publisher-Controlled Webhook Can Receive and Log Customer Communications
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This WhatsApp setup skill is mostly coherent, but it asks users to handle live customer messaging and long-lived Meta credentials while under-scoping sensitive webhook and token risks.
Install only after reviewing the sensitive parts: use a webhook endpoint under your own domain/cloud account, remove full webhook-body logging or redact customer fields, store Meta tokens in a secret manager, avoid non-expiring/admin tokens where possible, and require explicit review of recipient numbers and message content before any live send.
SKILL.md:168Publisher-Controlled Webhook Can Receive and Log Customer Communications
SKILL.md:439Unsafe String Interpolation Allows WhatsApp JSON Payload Injection
SKILL.md:143Non-Expiring Administrative API Token Is Stored in Plaintext Configuration
The README states that the skill is for Argentina/LATAM and includes templates ready in Spanish, specifically for Argentine SMEs. This appears to impose a locale/language default in the skill description without an explicit opt-in or a clear justification that the skill is strictly region-specific compliance tooling.
The README promotes automated WhatsApp sending from an agent and mentions compliance around opt-in and rate limits, but it does not explicitly warn that phone numbers and message contents are personal data that may be transmitted to Meta and other infrastructure. In a messaging automation skill, omission of privacy, consent, retention, and data-handling guidance can lead operators to deploy customer outreach flows without adequate notice, lawful basis, or safeguards.
The description states the skill is for Argentina/LATAM and specifically provides templates and guidance 'en español', which sets a fixed language/locale expectation. The file does not offer an alternative language choice or explicit opt-in for users outside that locale, which can violate language/locale policy requirements.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
emoji: "💬"
requires:
bins:
- curl
env: []
always: false
homepage: https://centriqs.io
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
> 🔒 **Seguridad:** `~/centriqs/whatsapp/config.md` puede contener tokens de acceso.
> Asegurar que el directorio tenga permisos `chmod 700 ~/centriqs/whatsapp/`.
> Nunca compartir el contenido de este archivo en canales públicos o grupos.
### config.md — Completar durante el setup
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Paso 2: Meta for Developers — Crear la App
1. Ir a `developers.facebook.com`
2. Click en **"My Apps"** → **"Create App"**
3. Seleccionar tipo: **"Business"**
4. Completar:
- App name: `[NombreEmpresa] WA Bot` (ej: `Centriqs WA Bot`)
The API example explicitly sets "language": { "code": "es_AR" }, and similar fixed locale usage appears throughout the template section. This natural-language/config choice enforces a specific locale rather than letting the user choose or clearly limiting use to a justified region-specific deployment.
The manifest and introductory description emphasize setup, compliance, templates, and integration guidance for the official Meta API. However, this section goes beyond configuration guidance and provides an operational function that performs real API POST requests to send WhatsApp templates, turning the skill into an active messaging tool rather than only a setup/documentation skill.
The shell example for wa_send_template hardcodes the template language to es_AR, which operationalizes a fixed locale for all sends. Without opt-in or documented regional restriction at the point of use, this is a natural-language locale policy concern.
The manifest describes end-to-end setup, webhook configuration, templates, compliance, and integration guidance. These lines additionally provide concrete commands for sending live text messages through the WhatsApp API, which is a broader operational capability than a pure setup/configuration guide.
This example shows direct transmission of message content and recipient identifiers to the external WhatsApp/Meta API using a bearer token. In an agent skill context, executable examples like this can enable unintended data disclosure, accidental customer contact, or misuse of a high-privilege token if the agent is allowed to run shell commands automatically.
Cuando el usuario escribe al número, el agente puede responder con texto libre durante las siguientes 24 horas. Ejemplo de respuesta automática vía API:
curl -X POST \
"https://graph.facebook.com/v23.0/${PHONE_NUMBER_ID}/messages" \
-H "Authorization: Bearer ${WA_ACCESS_TOKEN}" \
-H "Content-Type: application/json" \
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
- Los mensajes de los usuarios son datos personales sujetos a la **Ley 25.326** de Argentina
(Protección de Datos Personales). No almacenar conversaciones sin consentimiento explícito.
- El log de envíos en `~/centriqs/whatsapp/logs/` debe tener permisos restringidos
(`chmod 600`) si contiene nombres o números de clientes.
- Ante una brecha de seguridad que exponga el token, rotarlo inmediatamente desde
Meta Business Suite → Usuarios del sistema → Generar nuevo token.
No suspicious patterns detected.