Back to skill

Security audit

WhatsApp表情专业版

Security checks across malware telemetry and agentic risk

Overview

This skill is a WhatsApp marketing automation guide that clearly describes bulk and scheduled messaging, but it lacks consent/privacy safeguards and has mismatched activation text.

Review carefully before installing. This skill is not just GIF management; it guides automated WhatsApp outreach using customer phone numbers, scheduled sending, reports, and multiple accounts. Only use it for recipients who have clearly consented, keep contact/report files protected and minimized, and require explicit confirmation before any bulk or scheduled send.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Confidence
89% confidence
Finding
The activation text is ambiguous and mismatched to the skill’s stated purpose, which can cause the agent to invoke this skill in unrelated contexts. Because the skill exposes exec-enabled workflows, misactivation increases the chance of unintended command execution, external messaging actions, or processing of sensitive contact data outside the user’s actual intent.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill documents bulk WhatsApp messaging, scheduled sending, and rate-controlled mass delivery without clear consent, anti-spam, or abuse-prevention requirements. In this context, the capability is inherently dual-use and can facilitate spam, harassment, or policy-violating automated outreach at scale, especially when combined with scheduling and multi-account support.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The examples normalize creating customer contact lists, storing phone numbers, and exporting send reports without any privacy, retention, minimization, or access-control guidance. That increases the likelihood of mishandling personally identifiable information and campaign metadata, leading to privacy violations or accidental disclosure even if the tooling works as intended.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.