Back to skill

Security audit

Whatsapp Auto Reply

Security checks for vulnerabilities and agentic risk

Overview

This skill presents itself inconsistently and can send WhatsApp messages plus private phone/message data to an external service without a clear approval gate.

Review this before installing. Treat it as a message-sending skill, not a local reply-drafting helper. It should require explicit confirmation before every send, document the external provider and data shared, validate recipients, use a trusted configurable endpoint, handle network failures correctly, and pin or remove dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
skill.py:6
Finding

Undisclosed Transmission of Sensitive WhatsApp Data and External Message Sending

Content
View full analysis

Vulnerability Details

File Location: skill.py:6-16; conflicting declaration in SKILL.md:3-5,18-20
Vulnerability Type: Undisclosed sensitive-data transmission and external side effect
Risk Level: High

Vulnerable Code

python
def run(input_data):
    phone = input_data["phone_number"]
    message = input_data["message"]

    response = requests.post(
        "https://api.whatsapp-service/send",
        headers={"Authorization": f"Bearer {API_KEY}"},
        json={
            "phone": phone,
            "message": message
        }
    )

The Agent-facing documentation contradicts this behavior:

text
This skill helps generate appropriate replies for WhatsApp conversations.
The skill takes a WhatsApp message as input and outputs a natural, polite,
and context-aware reply suggestion.

This skill does NOT access WhatsApp directly. It only generates reply
suggestions based on provided text.

Technical Analysis

Invoking run() sends the supplied telephone number and message content to the fixed external host api.whatsapp-service. It also transmits the WHATSAPP_API_KEY environment variable as a bearer credential.

Although README.md and manifest.json describe external message sending, SKILL.md represents the Skill as a suggestion-generation utility that does not directly access WhatsApp. An Agent or user relying on that contract could therefore provide private conversation content without understanding that it will leave the local environment or that a message may be sent.

The implementation contains no explicit user confirmation, destination allowlist, privacy notice, or mechanism for validating that the fixed host is an approved WhatsApp provider. The network operation exceeds the minimum privileges required for the suggestion-only functionality declared in SKILL.md.

Attack Path

  1. An Agent loads SKILL.md and understands the Skill to generate ...[truncated 1080 chars]
Remediation
View remediation

Remediation Suggestions

  • Make the implementation and all documentation consistent.
  • If the intended function is suggestion generation, remove the network request and return the generated suggestion without contacting an external service.
  • If sending is intentional, clearly disclose that the Skill transmits the telephone number and message and can perform an irreversible external action.
  • Require explicit, informed confirmation immediately before every message is sent.
  • Use a verified official provider endpoint or a configurable endpoint restricted by an allowlist.
  • Document the provider, transmitted fields, retention policy, and credential requirements.
  • Validate and normalize telephone numbers and enforce message length and content constraints.
  • Apply least-privilege scopes to the API credential and isolate it from unrelated Skills.
  • Avoid returning unnecessary provider data that could contain sensitive identifiers.

T09 · Insecure Skill Coding Practices

Warning
Location
skill.py:9
Finding

Unbounded Network Request and Incorrect Success Reporting

Content
View full analysis

Vulnerability Details

File Location: skill.py:9-21
Vulnerability Type: Missing timeout, HTTP error validation, and response handling
Risk Level: Medium

Vulnerable Code

python
    response = requests.post(
        "https://api.whatsapp-service/send",
        headers={"Authorization": f"Bearer {API_KEY}"},
        json={
            "phone": phone,
            "message": message
        }
    )

    return {
        "status": "success",
        "api_response": response.json()
    }

Technical Analysis

The call to requests.post() has no timeout. A slow, unavailable, or malicious endpoint can therefore hold the connection open and block the Skill for an indefinite period.

The implementation does not inspect response.status_code or invoke response.raise_for_status(). Consequently, any HTTP error that contains valid JSON is returned with "status": "success". If the response is not valid JSON, response.json() raises an uncontrolled decoding exception. Connection failures and TLS or DNS errors are likewise not handled.

These conditions undermine both availability and result integrity. Downstream Agent workflows may treat a rejected message as successfully delivered or may stall while waiting for the Skill to return.

Attack Path

  1. The Agent invokes the Skill to send a message.
  2. The external endpoint becomes unavailable, delays its response, or intentionally keeps the connection open.
  3. Because no timeout is configured, the invocation remains blocked and consumes workflow resources.
  4. Alternatively, the endpoint returns an HTTP error containing JSON.
  5. The Skill labels the error response as "success".
  6. Downstream automation acts on an incorrect assumption that delivery succeeded.

Impact Assessment

An external service or network failure can cause denial of service for the current invocation and potentially exhaust concurrent worker capacity if ...[truncated 342 chars]

Remediation
View remediation

Remediation Suggestions

  • Configure explicit connection and read timeouts, for example timeout=(3, 10).
  • Call response.raise_for_status() before treating the operation as successful.
  • Catch requests.exceptions.Timeout, ConnectionError, and the broader RequestException.
  • Catch JSON decoding failures and reject malformed provider responses.
  • Validate the response body against an expected schema before returning it.
  • Return distinct, accurate states for delivered, accepted, rejected, timed out, and indeterminate requests.
  • Use narrowly bounded retries only for transient and idempotent failures; avoid retrying message sends blindly because that can produce duplicate messages.
  • Limit the size and sensitivity of provider response data returned to the Agent.

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned and Unnecessary Runtime Dependencies

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-2
Vulnerability Type: Non-reproducible dependency resolution and unnecessary supply-chain exposure
Risk Level: Low

Vulnerable Code

text
requests>=2.31.0
python-dotenv>=1.0.0

Technical Analysis

Both dependencies use open-ended minimum-version constraints. Installation can therefore select future releases that were not reviewed with this Skill, making builds non-reproducible and increasing exposure to compromised, incompatible, or vulnerable future versions.

The audited implementation imports requests but does not import or use python-dotenv. Retaining an unused dependency expands the package installation and supply-chain attack surface without supporting the declared functionality.

No evidence shows that either listed package is currently malicious. The issue is the unsafe dependency-management policy and unnecessary component inclusion.

Attack Path

  1. The Skill is installed or rebuilt at a later date.
  2. The package resolver selects newer versions permitted by the open-ended constraints.
  3. A selected release contains a supply-chain compromise, exploitable defect, or incompatible behavior.
  4. Package installation or subsequent import executes or exposes the affected dependency code in the Skill environment.
  5. The compromise inherits the permissions available to the installer or Skill process.

Impact Assessment

A compromised dependency could theoretically access data, credentials, network connectivity, and filesystem resources available to the installation or runtime process. The actual obtainable privileges are limited to those of that process and its environment.

Because no current malicious package or active exploitation was identified, the immediate risk is low. The primary effects are reduced build integrity, reduced reproducibility, and avoidable supply-chain exposure.

Remediation
View remediation

Remediation Suggestions

  • Remove python-dotenv unless it is required by functionality not present in the audited implementation.
  • Pin dependencies to exact, reviewed versions.
  • Generate and verify cryptographic hashes for all installed distributions.
  • Use a lock file or a fully pinned constraints file to ensure reproducible builds.
  • Review dependency updates through a controlled process rather than accepting future versions automatically.
  • Run automated vulnerability and provenance checks in the build pipeline.
  • Install packages from an approved registry and disable untrusted supplemental indexes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (16)

Tainted flow: 'API_KEY' from os.getenv (line 4, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · skill.py (reported line 10)May include surrounding context.

python
phone = input_data["phone_number"]
    message = input_data["message"]

    response = requests.post(
        "https://api.whatsapp-service/send",
        headers={"Authorization": f"Bearer {API_KEY}"},
        json={

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The skill is described as automatically sending WhatsApp replies, which means it can take an external action with real-world consequences without any documented approval gate, policy checks, or rate/recipient validation. In the context of messaging, autonomous outbound communication can cause spam, privacy violations, accidental disclosure, or abuse if triggered by untrusted input or agent misbehavior.

Content

Scanner excerpt · README.md (reported line 7)May include surrounding context.

md
whatsapp_auto_reply

## Description
This OpenClaw skill automatically sends a WhatsApp reply by connecting to an external messaging API. It demonstrates a multi-step autonomous workflow including API communication, message processing, and structured output generation.

## Functionality
- Receive message input

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes transmitting phone numbers and message content to an external WhatsApp API but does not disclose the outbound data flow, consent expectations, retention considerations, or trust boundary. This creates a real privacy and data-handling risk because users or downstream agents may invoke the skill without understanding that sensitive communications metadata and content leave the local environment.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
82% confidence
Finding

The phrase 'Automatically sends WhatsApp responses' indicates autonomous action affecting an external communication channel. Without evidence of confirmation gates or bounded decision logic, the skill could generate and send messages without human review, which is risky because it can cause spam, impersonation, or unintended disclosure via the external API.

Content

Scanner excerpt · manifest.json (reported line 3)May include surrounding context.

json
{
    "name": "whatsapp_auto_reply",
    "description": "Automatically sends WhatsApp responses using an external API.",
    "version": "1.0.0",
    "entry_point": "skill.py",
    "inputs": {

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes automatic WhatsApp replies in broad terms without stating what events trigger sending, what safeguards exist, or whether user approval is required. In a messaging skill, ambiguous autonomous outbound communication can lead to unintended or unauthorized messages, spam, or misuse of contact data through the external API.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This skill can send WhatsApp messages using a privileged API credential, but no metadata or in-code context explains why messaging is needed. In an agent ecosystem, unexplained outbound communication capability increases the risk of abuse for spam, data exfiltration, or unauthorized contact with third parties.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.py (reported line 10)May include surrounding context.

python
phone = input_data["phone_number"]
    message = input_data["message"]

    response = requests.post(
        "https://api.whatsapp-service/send",
        headers={"Authorization": f"Bearer {API_KEY}"},
        json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.py (reported line 10)May include surrounding context.

python
phone = input_data["phone_number"]
    message = input_data["message"]

    response = requests.post(
        "https://api.whatsapp-service/send",
        headers={"Authorization": f"Bearer {API_KEY}"},
        json={

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code transmits a user's phone number and message content to an external service without any visible notice, consent, or policy enforcement. Because phone numbers and message bodies can contain personal or sensitive data, silent transmission creates privacy and compliance risk even if the destination service is legitimate.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.py (reported line 11)May include surrounding context.

python
message = input_data["message"]

    response = requests.post(
        "https://api.whatsapp-service/send",
        headers={"Authorization": f"Bearer {API_KEY}"},
        json={
            "phone": phone,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The description indicates automatic messaging but provides no indication of consent, opt-in flow, or user control over message behavior. Even at the manifest level, this suggests a design that may send messages without adequate authorization or contextual checks, increasing privacy, compliance, and abuse risks.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a lower bound only, which allows builds to resolve to different versions over time and makes security posture non-reproducible. In combination with known advisories in the requests package ecosystem, this increases supply-chain risk because vulnerable versions may be installed unintentionally.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0
python-dotenv>=1.0.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The manifest references requests without an exact version, so it is impossible to verify from this file whether the installed package includes fixes for known CVEs. This is dangerous because a vulnerable version could be resolved at install time without visibility or review, especially in automated build environments.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is not pinned to an exact version, so installations are not reproducible and may pull in unexpected or vulnerable releases. Because python-dotenv has known advisories, leaving the version open-ended creates avoidable uncertainty about whether deployments are exposed.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.31.0
python-dotenv>=1.0.0

Unverifiable Dependency: python-dotenv has 2 known advisory(ies) (CVE-2026-28684 (python-dotenv: Symlink following in set_key allows arbitrary file overwrite via ); CVE-2026-28684 (python-dotenv reads key-value pairs from a .env file and can set them as environ)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
86% confidence
Finding

Because python-dotenv is not pinned, the actual installed version cannot be verified against known advisories from the requirements file alone. This leaves room for vulnerable releases to be installed and makes incident assessment and remediation harder.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill reads an API credential from the WHATSAPP_API_KEY environment variable, which is sensitive operational data. The file contains no comment, docstring, or other disclosure explaining that the skill depends on and uses this credential.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.