Back to skill

Security audit

WhatsApp FAQ Bot

Security checks across malware telemetry and agentic risk

Overview

This is an offline FAQ helper whose local file reads, writes, and stored knowledge base match its documented purpose.

Install only if you are comfortable with a local Python FAQ tool that can read files you point it at, store FAQ content under ~/.faq-bot, and write export files where requested. Use trusted FAQ sources, consider setting FAQ_BOT_DIR to a dedicated folder, and avoid letting untrusted chats trigger import or export commands automatically.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
79% confidence
Finding
The description includes broad triggers like 'build a knowledge base', 'add FAQ entries', 'search FAQs', and 'answer common questions', which are generic enough to match many unrelated requests. In an agent setting, this can cause over-activation of a file-reading/writing skill in contexts where the user did not intend to use this WhatsApp FAQ bot, increasing the chance of unintended data access or modification.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal