Back to skill

Security audit

What's app

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently lets an agent use the wacli WhatsApp CLI for user-approved sending, searching, syncing, and backfilling WhatsApp data.

Install only if you trust the upstream wacli project and are comfortable granting it access to your WhatsApp session and message history. Confirm recipients and message contents carefully before allowing sends, and consider using a pinned or reviewed wacli release where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 4
Vulnerability Type: Supply-chain risk caused by mutable, unpinned third-party installation sources
Risk Level: Medium

Vulnerable Code Snippet

yaml
metadata: {"clawdbot":{"emoji":"📱","requires":{"bins":["wacli"]},"install":[{"id":"brew","kind":"brew","formula":"steipete/tap/wacli","bins":["wacli"],"label":"Install wacli (brew)"},{"id":"go","kind":"go","module":"github.com/steipete/wacli/cmd/wacli@latest","bins":["wacli"],"label":"Install wacli (go)"}]}}

Technical Analysis

The Skill defines two installation methods for the wacli executable:

  • A third-party Homebrew tap, steipete/tap/wacli
  • A Go module using the mutable version selector @latest

Neither method pins the dependency to an immutable, reviewed release or commit. The @latest selector resolves dynamically at installation time, so the installed source can change after this Skill has been audited. The Homebrew formula is likewise referenced without an explicit version, artifact digest, or signature-verification requirement.

This creates a supply-chain trust gap: compromise of the upstream repository, package publication process, maintainer account, or Homebrew tap could result in installation of code that was not represented by the reviewed Skill content. The project contains no evidence that such a compromise has occurred; the finding concerns the unsafe dependency resolution mechanism.

Attack Path

  1. An attacker compromises an upstream maintainer account, source repository, release process, or the referenced Homebrew tap.
  2. The attacker publishes a malicious release or modifies the formula or source selected by the unpinned installation reference.
  3. A user or Agent installs wacli using the Skill's Go @latest option or third-party Homebrew formula.
  4. The package installation process or resulting executable runs attacker-controlled code with the privileges of ...[truncated 1135 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the Go @latest reference with a specific, reviewed semantic version:

    text
    github.com/steipete/wacli/cmd/wacli@vX.Y.Z
    

    For stronger immutability, pin and document the reviewed upstream commit corresponding to that release.

  2. Pin the Homebrew installation to a reviewed release rather than relying on the tap's current formula state. If the installation framework cannot enforce a specific formula revision, prefer a verifiable release artifact.

  3. Record and verify cryptographic checksums for downloaded release artifacts before execution. Use upstream signature verification where trusted signing metadata is available.

  4. Configure dependency automation to propose explicit version updates for review rather than resolving the newest upstream version during installation.

  5. Review installation scripts and dependency changes whenever the pinned version is updated, particularly because the installed tool can access authentication state and private message history.

  6. Run installation and use under a least-privileged account, and restrict access to ~/.wacli so that only the intended user can read its contents.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.