Back to skill

Security audit

tts-whatsapp-paid

Security checks across malware telemetry and agentic risk

Overview

The skill is not malicious, but it needs review because it enables bulk and scheduled WhatsApp outreach without strong built-in consent, authentication, or stop controls.

Install only for lawful, opted-in WhatsApp communications. Before using bulk, scheduled, or API modes, add explicit operator approval, recipient consent checks, opt-out handling, rate limits, API authentication, protected storage for contact/report files, and a clear way to stop scheduled or background sends.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The skill is explicitly designed for bulk, scheduled, and API-driven WhatsApp messaging, yet it does not place strong, prominent consent/privacy and anti-abuse warnings up front. In this context, the absence of clear guardrails increases the risk of spam, unauthorized outreach, and misuse of personal contact data at scale.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.