Back to skill

Security audit

WhatsApp表情搜索

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a WhatsApp GIF sender, but its trigger text points to unrelated SEO tasks while the instructions can download files and send WhatsApp messages.

Review before installing. Use this only for explicit WhatsApp GIF search/send workflows, verify the contact and selected media before sending, and be aware that it may download remote files, create local MP4 files, and send a WhatsApp message. The publisher should fix the SEO trigger text before broad distribution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The trigger condition says to use this skill for SEO optimization, keyword analysis, ranking improvement, and search-traffic optimization, which is unrelated to a WhatsApp GIF search/send tool. This mismatch can cause the agent to invoke the skill in inappropriate contexts, leading to unexpected execution of network downloads, file writes, and outbound messaging behavior when the user did not intend to use this capability.

Vague Triggers

High
Confidence
99% confidence
Finding
The trigger condition is both unrelated and broad, making accidental or unintended invocation likely. In an agent setting, ambiguous triggers can route unrelated user requests into a skill that performs external network access, local file manipulation, and message sending, which materially increases the risk of unintended side effects.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to download external media, transform files with ffmpeg, and send the resulting content to a WhatsApp contact, but it does not provide a clear up-front warning about these side effects. Without explicit disclosure and confirmation, users may not realize the skill performs network fetches, writes files to local storage, and sends outbound messages to third parties.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.