Back to skill

Security audit

Whatsapp Image Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mainly a WhatsApp image-sending helper, but its trigger instructions point to unrelated media tasks that could cause the agent to send files in the wrong context.

Review this skill carefully before installing. Use it only for explicit requests to send one JPG/PNG/GIF image to a specific WhatsApp number, and confirm the recipient, file path or URL, and caption before execution. Do not rely on its current trigger text for video, audio, conversion, or dubbing tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill claims the free edition only supports images, but multiple sections describe '基础文件传输' and generic file handling workflows. This inconsistency can cause an agent or user to treat non-image documents as permitted and transmit unintended files through WhatsApp, creating policy bypass and data leakage risk.

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The trigger-condition section instructs use of this skill for unrelated tasks such as video processing, audio editing, media conversion, and dubbing, which do not match the implemented capability. In agentic environments, trigger text influences tool selection, so this mismatch can cause the skill to be invoked in inappropriate contexts and exfiltrate local or downloaded media via messaging workflows.

Vague Triggers

High
Confidence
94% confidence
Finding
Ambiguous or contradictory invocation scope is a real security problem for agent skills because it can cause automatic selection for tasks outside intended boundaries. Here, unrelated media-task triggers increase the chance that the agent uses a networked messaging tool when the user asked for editing or conversion, potentially sending sensitive files or contacting recipients unintentionally.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill describes downloading external content and transmitting it to third-party services and recipients, but does not present a prominent upfront warning about network transfer, recipient impact, or privacy implications before operational steps. In a messaging skill, this raises the risk of users or agents sending data externally without fully informed consent, especially when local files are copied from workspace or /tmp.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.