Back to skill

Security audit

Whop

Security checks across malware telemetry and agentic risk

Overview

This Whop skill is a coherent business and API guide with disclosed local notes and optional Whop credentials, so it needs normal care but not Review.

Install this if you want Whop-specific business and developer guidance. Before using advanced features, keep API keys and webhook secrets out of memory files, prefer sandbox credentials for tests, separate sandbox and production notes, and avoid saving customer data, payment details, or secret values in ~/whop/.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The setup instructs the agent to determine within the first few exchanges when the skill should auto-activate for broad topics such as Whop, products, plans, memberships, payouts, or app installs. This can cause the skill to attach itself to future conversations more broadly than the user intended, increasing the chance of unintended invocation in sensitive business, payment, or support contexts. In a skill that touches payments, disputes, webhooks, and business operations, overbroad activation raises the risk of incorrect assistance, privacy overreach, or accidental action planning in the wrong context.

Vague Triggers

Low
Confidence
80% confidence
Finding
The activation guidance says to figure out within the first few exchanges when the skill should activate in the future, but it does not define firm boundaries or require explicit user consent before persistent activation behavior is inferred. That ambiguity can lead to the assistant enabling the skill based on conversational cues rather than a clear authorization decision, which is a policy and safety weakness even if not overtly malicious. The surrounding Whop context makes this more important because the skill covers financially and operationally sensitive areas.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.