WhatsApp Image Send

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed WhatsApp media-sending helper, but users should confirm the file source and recipient before it downloads or sends anything.

Install only if you want the agent to download files and send them through your WhatsApp account. Confirm the URL or source file, recipient phone number, caption, and filename before use; avoid untrusted URLs or unusual filenames, and remove the workspace copy afterward if the media is sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs the agent to download remote content to local storage and delete temporary files, but it provides no user-facing notice that local files will be created, copied, and removed. This can cause unintended local state changes and reduce user awareness during a workflow that touches the filesystem and external resources.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill downloads content from a URL and then transmits it over WhatsApp, but it does not disclose the privacy and external-transfer implications of fetching remote content and sending media to a third-party messaging platform. Users may not realize their data, metadata, or chosen recipient information is being sent outside the local environment.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal