Back to skill

Security audit

Whatsapp Msg Manager Free

Security checks across malware telemetry and agentic risk

Overview

This WhatsApp messaging skill is mostly coherent, but it grants outbound messaging authority with inconsistent confirmation guidance and overly broad activation wording.

Install only if you intend to connect a WhatsApp Business account through the connector plugin. Require a visible preview and explicit confirmation before every message send, and avoid using this skill for generic API, webhook, or system-integration work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The document claims all write actions require explicit user confirmation, yet many examples invoke the send command directly. In an agentic environment, inconsistent safety guidance can cause unintended message transmission without a reliable preview/consent step, leading to privacy leaks, spam, or unauthorized outbound communications.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger conditions are broad enough that the skill may activate for generic API integration, webhook, or system connection requests beyond its narrow WhatsApp texting scope. Overbroad invocation criteria increase the chance an agent selects this skill in the wrong context and performs sensitive connector actions or exposes account data unnecessarily.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.