Back to skill

Security audit

Whatsapp Msg

Security checks for vulnerabilities and agentic risk

Overview

This WhatsApp automation skill is purpose-related, but it asks for broad messaging, export, syncing, command execution, and credential-adjacent access without enough scoping or provenance controls.

Review before installing. Use this only for explicitly authorized WhatsApp accounts and chats, verify the exact source and integrity of wacli and any scripts before execution, avoid running the agent or tools as administrator, scope exports and sync to specific chats/date ranges, disable media download and webhook forwarding unless needed, and protect or delete generated contact and message archive files.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:136
Finding

Unpinned and Unverifiable Executable Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:136-142 and SKILL.md:313
Vulnerability Type: Supply-chain dependency ambiguity
Risk Level: High

Vulnerable Code

bash
python wa_batch_sender.py \
  --store ~/.wacli \
  --recipients "contacts.json" \
  --message "..." \
  --rate_limit 3 \
  --retry 3 \
  --dry_run false

English rendering of the dependency declaration at line 313:

text
wacli | CLI tool | Required | Install through a package manager or compile from source

Technical Analysis

The Skill directs the Agent to execute wa_batch_sender.py, but the audited package contains only SKILL.md; the referenced Python script is not included. Consequently, script resolution depends on the Agent's current working directory and local environment.

The required wacli executable is similarly identified only by a generic command name. The documentation provides no canonical package identifier, trusted repository URL, pinned version or commit, cryptographic checksum, or signature-verification procedure. The instruction to install it through an unspecified package manager or compile it from unspecified source leaves dependency provenance unresolved.

These conditions create dependency-confusion, name-collision, and local executable-substitution risks. A malicious file with the expected script name or a malicious package exposing the expected CLI name could be selected without an obvious change to the documented command.

Attack Path

  1. An attacker publishes a misleading or compromised package that installs an executable named wacli, or places a malicious wa_batch_sender.py in a directory from which the Agent runs the documented command.
  2. The user or Agent follows the Skill's installation or execution instructions without a canonical source or integrity information.
  3. Python resolves and executes the attacker-controlled local script, or the shell resolves the malicio ...[truncated 917 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include wa_batch_sender.py in the Skill package and subject it to source review.
  2. Invoke bundled scripts through a validated, absolute Skill-relative path rather than relying on the current working directory.
  3. Document the canonical publisher, repository, and exact package identifier for wacli.
  4. Pin dependencies to an immutable version or commit and publish expected cryptographic checksums.
  5. Require signature or checksum verification before installation and execution.
  6. Resolve the executable path explicitly and verify its provenance before invoking it.
  7. Run the dependency in a least-privilege sandbox with access restricted to explicitly approved input and output directories.
  8. Prevent the process from reading unrelated environment variables, credential stores, and filesystem locations.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:442
Finding

Generic Recommendation to Run Failed Commands with Administrator Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:442
Vulnerability Type: Unsafe privilege-escalation guidance
Risk Level: Medium

Vulnerable Code

English rendering of the complete troubleshooting row:

text
Insufficient permissions | The current user lacks read/write permission | Check file permissions and run as administrator

Technical Analysis

The troubleshooting guidance recommends running commands as administrator whenever a read/write permission failure occurs. It does not identify which command requires elevation, explain why elevated access is legitimate, limit elevation to a narrowly scoped operation, or require verification of the executable first.

Permission errors commonly result from incorrect paths, ownership, output-directory selection, or attempts to access resources outside the task's legitimate scope. Elevating the entire Agent or an unverified dependency converts a limited permission failure into execution with substantially broader system access. This is particularly risky in combination with the unverified executable dependencies identified elsewhere in the Skill.

Attack Path

  1. An untrusted, substituted, or incorrectly configured executable reports a permission error.
  2. The user follows the Skill's generic troubleshooting advice and reruns the command or Agent with administrator privileges.
  3. The executable now runs outside the original least-privilege boundary.
  4. Malicious code can access or modify administrator-protected resources that were unavailable during the initial execution.
  5. Depending on the operating system and granted privileges, the executable could alter system files, other users' data, protected configuration, or credential material.

Impact Assessment

Exploitation could elevate the impact of malicious or compromised dependencies from user-level code execution to administrator-level access. Potential scope includes system-wide files, protect ...[truncated 320 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the generic instruction to run commands as administrator.
  2. Direct users to verify the target path, ownership, access-control entries, and required operation before changing privileges.
  3. Recommend selecting a user-owned output directory when only output-file access is required.
  4. If elevation is genuinely necessary, document the exact verified command and narrowly scoped privileged operation.
  5. Never elevate the entire Agent session or an unverified third-party executable.
  6. Require dependency provenance and integrity checks before any privileged execution.
  7. Apply least-privilege filesystem permissions rather than broad recursive permission changes.
  8. Record and review privileged operations, and require explicit user confirmation immediately before execution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes bulk messaging, history archiving, contact export, persistent file output, and webhook/event syncing without placing a prominent consent, privacy, and data-impact warning directly before those operations. In practice, this can normalize high-risk handling of personal communications and enable mass collection, retention, or transmission of sensitive content without informed user approval or recipient considerations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation criteria are extremely broad and invite use whenever efficiency, automation, or workflow optimization is desired, rather than only for narrowly defined WhatsApp-management tasks. Overbroad triggers increase the chance the agent invokes a high-impact skill in unrelated contexts, leading to unnecessary access to messaging data, command execution, or bulk outbound actions without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description explicitly states '支持中文交互,无需复杂配置即开即用', and the rest of the document is presented as a Chinese-first interaction model without opt-in or alternatives. This can violate language/locale policy when a skill mandates a specific language rather than allowing user preference.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill claims command-execution safety through a whitelist and avoidance of user-input concatenation, but the document simultaneously instructs the agent to run arbitrary CLI tools and scripts such as Python programs and shell commands. In an agent context with exec/write/read permissions, this mismatch can cause operators to overtrust the skill and permit unsafe command execution paths that process attacker-controlled parameters or access sensitive local data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages broad backfill, archiving, media download, and long-term storage of chat histories and related metadata, including output to JSON/CSV/SQLite and database archival. This materially increases exposure of sensitive personal and business communications, especially when retention scope, encryption, access controls, and legal basis are not enforced as hard requirements.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The continuous sync guidance promotes persistent capture of message events and optional forwarding to webhooks, with auto-download of media and JSONL output. This creates an always-on surveillance and onward-disclosure channel for sensitive communications, and if webhook endpoints, files, or credentials are misconfigured, it can lead to large-scale leakage beyond the original messaging platform.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The contact export instructions direct extraction of structured personal information into external files, including vCard/JSON export and identifier cross-referencing. Exportable contact datasets are easy to copy, aggregate, and misuse, so providing this capability without strong warnings, consent boundaries, and output protection increases privacy and unauthorized-disclosure risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.