Waboxapp

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Waboxapp/Membrane integration for WhatsApp-related API work, and I found no hidden code, exfiltration, or malicious behavior.

Install only if you trust Membrane and intend to connect a Waboxapp account. Review recipients, message contents, media, contact details, and raw proxy paths before running actions; prefer listed Membrane actions over raw proxy requests; revoke the Membrane/Waboxapp connection when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill enables message sending and arbitrary proxied API requests to an external service without clearly warning that user data may be transmitted off-platform. In a messaging integration, this can lead to unintended disclosure of sensitive content or metadata if the agent invokes these capabilities without explicit user awareness and confirmation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal