Back to skill

Security audit

P-API - WhatsApp API

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent WhatsApp automation API skill, but it exposes powerful messaging and account-management actions with weak safety and credential-handling guidance.

Review this skill carefully before installing. Use least-privilege, instance-scoped API keys where possible; avoid storing real keys in repository or agent-readable Markdown; confirm recipients, groups, destructive deletes, and webhook/WebSocket destinations before use; and enable only the event types needed for trusted HTTPS/WSS endpoints.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:56
Finding

API Credential Stored in Plaintext Configuration and Exposed in Command Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56-69
Vulnerability Type: Plaintext sensitive credential handling
Risk Level: Medium

Vulnerable Code

markdown
Before using, configure in TOOLS.md:

```markdown
### P-API (WhatsApp)
- Base URL: https://your-server.com
- API Key: your-api-key
- Default Instance: instance-name
text

```bash
curl -X GET "https://your-server.com/api/instances" \
  -H "x-api-key: YOUR_KEY"

Technical Analysis

The skill instructs users to store an API key directly in a Markdown configuration file and insert it literally into a command-line argument. It does not recommend an environment variable, protected secret store, restrictive file permissions, output redaction, or shell-history controls.

A real credential placed in TOOLS.md may become accessible through local file reads, source-control mistakes, backups, diagnostic archives, agent context collection, or other processes and users with access to the workspace. Supplying the credential directly in a command can additionally expose it through shell history, command logging, debugging output, or process inspection, depending on the execution environment.

The shown values are placeholders rather than embedded live credentials. The vulnerability arises from the documented credential-handling pattern that users are instructed to adopt.

Attack Path

  1. A user follows the documentation and places a valid P-API key and server URL in TOOLS.md.
  2. The configuration file, shell history, execution log, backup, or captured agent context becomes accessible to an unauthorized party.
  3. The unauthorized party extracts the API key and corresponding base URL.
  4. The party supplies the stolen key through the documented x-api-key header.
  5. The party invokes API operations available to that key, potentially including instance administration, message transmission, group management, catalog modificat ...[truncated 1092 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace plaintext credential instructions with an environment-variable or secret-manager workflow:

    bash
    export P_API_BASE_URL="https://your-server.com"
    export P_API_KEY="$(secret-manager read p-api/key)"
    
    curl -X GET "${P_API_BASE_URL}/api/instances" \
      -H "x-api-key: ${P_API_KEY}"
    
  2. Do not store real credentials in TOOLS.md, source-controlled files, examples, or agent-readable project documentation.

  3. If local secret files are unavoidable, keep them outside the repository, enforce restrictive permissions such as chmod 600, and exclude them through .gitignore.

  4. Disable or sanitize shell history and command logging when commands may contain secrets.

  5. Ensure agents, scripts, and diagnostics redact x-api-key header values from prompts, output, traces, and error reports.

  6. Apply server-side least privilege by issuing instance-scoped keys with only the required operations.

  7. Support key expiration and rotation, and immediately revoke keys suspected of exposure.

  8. Add secret scanning to source-control and CI workflows to detect accidentally committed API keys.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/catalog.md (reported line 74)May include surrounding context.

Remover Produto

bash
DELETE /api/instances/:id/catalog/product/:productId

Coleções (Categorias)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/catalog.md (reported line 101)May include surrounding context.

Remover Coleção

bash
DELETE /api/instances/:id/catalog/collection/:collectionId

Os produtos não são deletados, apenas removidos da coleção.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents powerful actions such as sending WhatsApp messages, creating and deleting instances, managing groups, and configuring webhooks, but it does not warn users about the risk of unintended bulk messaging, service disruption, privacy issues, or destructive instance changes. In an agent setting, omission of these guardrails increases the chance that a user or downstream automation triggers high-impact actions without informed confirmation or scope checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file describes a product deletion operation (DELETE /api/instances/:id/catalog/product/:productId) but provides no warning about its destructive effect on catalog data. Under the markdown-specific warning criterion, skills should disclose behaviors that can affect user data or system integrity, especially irreversible or potentially harmful actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file describes operations to add/remove participants, promote/demote admins, change group settings, and leave a group, all of which can affect user data, access, or system integrity. The document presents these actions as straightforward API calls but does not include cautions about authorization, user impact, or irreversible/disruptive effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The configuration documents a keyword-based trigger using contains with values like oi, olá, bom dia, and boa tarde, which are common conversational phrases in everyday messages. Because the documentation does not provide exclusion conditions or scope limits, this creates an ambiguous activation boundary for when the integration should start.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The webhook documentation instructs users to send message and status events to an external URL but does not prominently warn that enabling this causes conversation metadata and potentially message content to leave the system boundary. This omission can lead to inadvertent data disclosure to third-party infrastructure, especially if users enable broad event sets without understanding the privacy and trust implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The WebSocket integration documentation describes streaming events to an external server over a persistent connection without clearly warning that enabling it continuously exports operational and messaging data outside the platform. Because persistent channels can increase the volume and immediacy of exposed data, users may unknowingly create a broader data-sharing surface than intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown documentation presents all instructions, labels, and examples in Portuguese, which imposes a specific language on users. Under the policy, language-specific content should either provide user choice or clearly justify the locale restriction; neither is present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file includes a collection deletion endpoint and only clarifies that products are not deleted, but it does not explicitly warn that the collection itself will be removed. The documentation should make the data-impacting nature of this operation clear to users before they invoke it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

A language or locale policy issue can arise when a skill or reference forces a specific language without offering alternatives or documenting that the content is region-specific. Here, all headings and descriptions are Portuguese-only, with no indication that the user can choose another language or that the scope is intentionally limited.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.