Back to skill

Security audit

whatclaw-whatsapp-integration

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it can send real WhatsApp messages and local files externally with too little confirmation or path control.

Review this before installing on any account that can send real WhatsApp messages. Use it only with trusted operators, carefully controlled recipient sets, and non-sensitive media paths; avoid running it in automated contexts where untrusted text could trigger commands. A safer version should add preview/confirmation before sends, restrict local media to an approved directory, and document local storage retention and permissions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
word-trigger.js:259
Finding

Unrestricted Local File Disclosure Through WhatsApp Media Transmission

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The send examples describe transmitting message text, local file paths, and remote media URLs through WhatsApp/OpenClaw, but the skill omits a clear warning that this content may leave the local environment and be sent to external services. Users may inadvertently transmit sensitive message content, internal filesystem paths, or confidential media without understanding the privacy implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script can send WhatsApp messages directly to all numbers in a stored set based only on a parsed phrase, with no explicit confirmation, approval step, or dry-run safeguard before transmission. In an agent or automation context, mis-parsed input, prompt injection, or accidental invocation could trigger real outbound messages to multiple recipients, causing privacy, spam, or reputational harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documentation states that whitelist and message-status data are stored in local files, but it does not explicitly warn about the security and privacy implications of storing phone numbers and message metadata on disk. This can lead operators to use the skill on shared or insecure systems without realizing that sensitive contact data may persist locally and be exposed through backups, logs, or lax file permissions.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
word-trigger.js:66