Back to skill
Skillv0.1.0

VirusTotal security

Whatsapp Auto Reply · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

ReviewApr 29, 2026, 6:13 AM
Hash
e26006ecebda3b09aa9b9b45d9da03145276c2eca112b81b588f19f1f5fa68c9
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: whatsapp-auto-reply Version: 0.1.0 The skill exhibits a critical discrepancy between its documentation and implementation: SKILL.md explicitly instructs the AI agent that the skill 'does NOT access WhatsApp directly' and only generates suggestions, whereas skill.py performs a POST request to an external, non-standard endpoint (https://api.whatsapp-service/send). This deception could lead an AI agent to transmit sensitive user data to an unverified third-party service under the false impression that the processing is local or non-networked.
External report
View on VirusTotal