T09 · Insecure Skill Coding Practices
- Location
word-trigger.js:259- Finding
Unrestricted Local File Disclosure Through WhatsApp Media Transmission
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill does what it says, but it can send real WhatsApp messages and local files externally with too little confirmation or path control.
Review this before installing on any account that can send real WhatsApp messages. Use it only with trusted operators, carefully controlled recipient sets, and non-sensitive media paths; avoid running it in automated contexts where untrusted text could trigger commands. A safer version should add preview/confirmation before sends, restrict local media to an approved directory, and document local storage retention and permissions.
word-trigger.js:259Unrestricted Local File Disclosure Through WhatsApp Media Transmission
The send examples describe transmitting message text, local file paths, and remote media URLs through WhatsApp/OpenClaw, but the skill omits a clear warning that this content may leave the local environment and be sent to external services. Users may inadvertently transmit sensitive message content, internal filesystem paths, or confidential media without understanding the privacy implications.
The script can send WhatsApp messages directly to all numbers in a stored set based only on a parsed phrase, with no explicit confirmation, approval step, or dry-run safeguard before transmission. In an agent or automation context, mis-parsed input, prompt injection, or accidental invocation could trigger real outbound messages to multiple recipients, causing privacy, spam, or reputational harm.
The skill documentation states that whitelist and message-status data are stored in local files, but it does not explicitly warn about the security and privacy implications of storing phone numbers and message metadata on disk. This can lead operators to use the skill on shared or insecure systems without realizing that sensitive contact data may persist locally and be exposed through backups, logs, or lax file permissions.
Detected: suspicious.dangerous_exec