whatsapp-pro2

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Membrane-based WhatsApp Business integration, but users should supervise any raw API calls that can change account data.

Install only if you intend to connect a WhatsApp Business account through Membrane. Prefer Membrane's listed actions, review permissions during connection, and require explicit confirmation before sending messages, changing templates, deleting data, or using proxy requests with POST, PUT, PATCH, or DELETE.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
79% confidence
Finding
The skill explicitly documents arbitrary proxy requests to an external API and emphasizes that authentication headers are injected automatically, but it does not clearly instruct the agent to obtain user confirmation before transmitting data or performing state-changing requests. In an agent setting, this can lead to unintended disclosure of user or business data to a third-party service or accidental mutation of remote resources.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal