Back to skill

Security audit

WhatsApp Business LATAM (Cloud API)

Security checks for vulnerabilities and agentic risk

Overview

This WhatsApp setup skill is mostly coherent, but it asks users to handle live customer messaging and long-lived Meta credentials while under-scoping sensitive webhook and token risks.

Install only after reviewing the sensitive parts: use a webhook endpoint under your own domain/cloud account, remove full webhook-body logging or redact customer fields, store Meta tokens in a secret manager, avoid non-expiring/admin tokens where possible, and require explicit review of recipient numbers and message content before any live send.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

other

Error
Location
SKILL.md:168
Finding

Publisher-Controlled Webhook Can Receive and Log Customer Communications

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:439
Finding

Unsafe String Interpolation Allows WhatsApp JSON Payload Injection

Content
View full analysis
... wa_send_template() { local numero="$1" local template_name="$2" shift 2 local params="" for var in "$@"; do params="${params}{\"type\":\"text\",\"text\":\"${var}\"}," done params="${params%,}" # Quitar última coma curl -s -X POST \ "https://graph.facebook.com/v23.0/${PHONE_NUMBER_ID}/messages" \ -H "Authorization: Bearer ${WA_ACCESS_TOKEN}" \ -H "Content-Type: application/json" \ -d "{ \"messaging_product\": \"whatsapp\", \"to\": \"${numero}\", \"type\": \"template\", \"template\": { \"name\": \"${template_name}\", \"language\": {\"code\": \"es_AR\"}, \"components\": [{ \"type\": \"body\", \"parameters\": [${params}] }] } }" } ``` ### Technical Analysis The function constructs JSON by concatenating shell variables directly into a quoted string. The following values are not JSON-escaped or validated: - `numero` - `template_name` - Every template variable in `"$@"` Shell quoting prevents ordinary shell metacharacters inside these variables from becoming separate shell commands in this particular construction. However, it does not provide JSON escaping. An input containing a double quote, backslash, control character, or crafted JSON fragment can terminate the intended JSON string and inject or replace JSON fields. For example, a malicious template variable can close its `"text"` property and add additional object properties or elements. Even non-malicious customer data containing quotation marks or line breaks can produce malformed requests. Because the request is authenticated with `WA_ACCESS_TOKEN`, modified payloads are submi ...[truncated 1478 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:143
Finding

Non-Expiring Administrative API Token Is Stored in Plaintext Configuration

Content
View full analysis
", "WA_ACCESS_TOKEN": "" } } } } } ``` ### Technical Analysis The setup combines three security-sensitive choices: 1. Creation of an administrative System User. 2. Issuance of a token configured never to expire. 3. Storage of that token in plaintext Markdown or JSON configuration. Although the Skill recommends directory mode `700`, directory permissions alone do not guarantee that the credential file has restrictive permissions. Existing files may retain broade ...[truncated 1923 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that the skill is for Argentina/LATAM and includes templates ready in Spanish, specifically for Argentine SMEs. This appears to impose a locale/language default in the skill description without an explicit opt-in or a clear justification that the skill is strictly region-specific compliance tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README promotes automated WhatsApp sending from an agent and mentions compliance around opt-in and rate limits, but it does not explicitly warn that phone numbers and message contents are personal data that may be transmitted to Meta and other infrastructure. In a messaging automation skill, omission of privacy, consent, retention, and data-handling guidance can lead operators to deploy customer outreach flows without adequate notice, lawful basis, or safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description states the skill is for Argentina/LATAM and specifically provides templates and guidance 'en español', which sets a fixed language/locale expectation. The file does not offer an alternative language choice or explicit opt-in for users outside that locale, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
emoji: "💬"
    requires:
      bins:
        - curl
      env: []
    always: false
    homepage: https://centriqs.io

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

text

> 🔒 **Seguridad:** `~/centriqs/whatsapp/config.md` puede contener tokens de acceso.
> Asegurar que el directorio tenga permisos `chmod 700 ~/centriqs/whatsapp/`.
> Nunca compartir el contenido de este archivo en canales públicos o grupos.

### config.md — Completar durante el setup

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
### Paso 2: Meta for Developers — Crear la App

1. Ir a `developers.facebook.com`
2. Click en **"My Apps"** → **"Create App"**
3. Seleccionar tipo: **"Business"**
4. Completar:
   - App name: `[NombreEmpresa] WA Bot` (ej: `Centriqs WA Bot`)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The API example explicitly sets "language": { "code": "es_AR" }, and similar fixed locale usage appears throughout the template section. This natural-language/config choice enforces a specific locale rather than letting the user choose or clearly limiting use to a justified region-specific deployment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest and introductory description emphasize setup, compliance, templates, and integration guidance for the official Meta API. However, this section goes beyond configuration guidance and provides an operational function that performs real API POST requests to send WhatsApp templates, turning the skill into an active messaging tool rather than only a setup/documentation skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The shell example for wa_send_template hardcodes the template language to es_AR, which operationalizes a fixed locale for all sends. Without opt-in or documented regional restriction at the point of use, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes end-to-end setup, webhook configuration, templates, compliance, and integration guidance. These lines additionally provide concrete commands for sending live text messages through the WhatsApp API, which is a broader operational capability than a pure setup/configuration guide.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

This example shows direct transmission of message content and recipient identifiers to the external WhatsApp/Meta API using a bearer token. In an agent skill context, executable examples like this can enable unintended data disclosure, accidental customer contact, or misuse of a high-privilege token if the agent is allowed to run shell commands automatically.

Content

Scanner excerpt · SKILL.md (reported line 689)May include surrounding context.

Cuando el usuario escribe al número, el agente puede responder con texto libre durante las siguientes 24 horas. Ejemplo de respuesta automática vía API:

bash
curl -X POST \
  "https://graph.facebook.com/v23.0/${PHONE_NUMBER_ID}/messages" \
  -H "Authorization: Bearer ${WA_ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 749)May include surrounding context.

md
- Los mensajes de los usuarios son datos personales sujetos a la **Ley 25.326** de Argentina
(Protección de Datos Personales). No almacenar conversaciones sin consentimiento explícito.
- El log de envíos en `~/centriqs/whatsapp/logs/` debe tener permisos restringidos
(`chmod 600`) si contiene nombres o números de clientes.
- Ante una brecha de seguridad que exponga el token, rotarlo inmediatamente desde
Meta Business Suite → Usuarios del sistema → Generar nuevo token.

Static analysis

No suspicious patterns detected.