Back to skill

Security audit

WhatsApp GIF工具

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a WhatsApp GIF helper, but its instructions are inconsistent and include broad messaging automation claims without clear user controls.

Review before installing. Use it only for user-directed WhatsApp GIF search/conversion/sending, and require explicit approval before downloads, file writes, ffmpeg execution, or sending messages to recipients. The SEO text and batch messaging claims should be corrected or removed by the publisher.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest description mixes unrelated SEO optimization guidance into a WhatsApp GIF skill, creating a capability/intent mismatch. This can cause agents or users to invoke the skill in inappropriate contexts and trust misleading metadata, increasing the chance of unintended execution of read/exec/write operations.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The core feature text describes ranking/search-traffic optimization rather than GIF messaging behavior, which is inconsistent with the skill purpose. In an agent ecosystem, misleading capability descriptions can route user requests to the wrong skill and obscure side effects such as network access, file writes, and message sending.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Advertising batch multi-channel messaging and template/variable injection expands the apparent behavior beyond a narrow GIF helper into mass messaging automation. That broader framing materially increases abuse potential for spam, unintended broadcasts, or templated content injection, especially when the skill also exposes exec/write capabilities.

Vague Triggers

High
Confidence
97% confidence
Finding
The invocation guidance is vague and mismatched, telling agents to use this skill in unrelated SEO contexts. In agent selection pipelines, this can mis-trigger the skill for tasks outside its intended scope, leading to unnecessary command execution, file handling, or messaging actions under false assumptions.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The markdown includes concrete commands that download remote media, run ffmpeg, and copy output into the workspace, but it does not prominently warn about network, storage, and message-delivery side effects. Users or agents may treat this as harmless content transformation when it actually performs external fetches and persistent file operations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.