Whatsapp Ultimate

Security checks across malware telemetry and agentic risk

Overview

The skill mostly does what it says (WhatsApp group and contact features) but includes undeclared, invasive scripts that patch your OpenClaw source and read/write local WhatsApp auth and contact data — behaviour that is privacy-sensitive and disproportionate unless you explicitly expect code-modifying patches.

This skill contains scripts that will find and patch your local OpenClaw source and read/write WhatsApp auth and contact files in your home directory. Before running anything: (1) Review the scripts line-by-line and confirm you understand each file edit; (2) Back up your OpenClaw repo and credentials directories; (3) Prefer running the contact fetch and group-create scripts manually (not blind automation) and inspect their outputs; (4) If you don't want your inbound messages persisted or contact lists written to disk, do not run apply-history-fix.sh or wa-fetch-contacts.ts; (5) If you must apply patches, run them in a controlled/dev environment first and inspect diffs (e.g., git diff) before committing; (6) Consider legal/privacy implications of extracting contacts and resolving LIDs in your jurisdiction. The behavior is explainable for the stated features but is invasive and should not be installed without careful manual review and backups.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal