Back to skill

Security audit

WhatsApp语音消息免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is for sending real WhatsApp voice messages, but its trigger and recipient scope are too broad for that authority.

Review before installing. Only use this skill when you explicitly want to generate and send a WhatsApp voice message, verify the recipient every time, prefer --no-send preview first, and avoid using it for ordinary translation or localization tasks.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill claims the free edition does not support group sending, yet the CLI documentation permits a group ID in `--target`. This inconsistency can cause an agent or user to invoke messaging against groups unexpectedly, expanding the audience of outbound content beyond the documented safety boundary and increasing privacy and misuse risk.

Intent-Code Divergence

Low
Confidence
88% confidence
Finding
The trigger condition describes translation, multilingual conversion, and localization scenarios rather than TTS-to-WhatsApp message sending. This mismatch can route unrelated requests into a skill that performs real-world message transmission, increasing the chance of accidental invocation with sensitive text or unintended recipients.

Vague Triggers

High
Confidence
95% confidence
Finding
An overly broad, mismatched trigger condition is dangerous here because the skill has `exec` capability and can send messages to real WhatsApp targets. Unintended invocation could cause the agent to process arbitrary text and initiate external communication without the user's clear intent, potentially leaking private content or spamming contacts.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill lacks a prominent warning that it may send content to real WhatsApp contacts and process phone numbers, which are sensitive personal data. Without clear user-facing notice and confirmation, users may unknowingly expose private message content or transmit to unintended recipients.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.