Back to skill

Security audit

Whatsapp Style Guide Free

Security checks across malware telemetry and agentic risk

Overview

This looks like a WhatsApp formatting guide, but it asks for command execution and contains unrelated or inconsistent capability text that should be reviewed before use.

Review this skill before installing. It does not show data theft or destructive behavior, but a safer version should remove exec permission, remove nonexistent command examples and ping guidance, and delete the unrelated product-spec capability blocks so the skill is limited to WhatsApp formatting help.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is presented as a static formatting guide, but these sections describe parameter-driven operations and create/query/export behaviors as if the skill can actively process user input. This mismatch can mislead an agent or user into granting the skill broader authority than intended, increasing the risk of unsafe invocation paths or unintended tool usage.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The file abruptly introduces unrelated product-spec extraction capabilities such as Bluetooth version, battery life, waterproof rating, and weight, which do not match the WhatsApp formatting purpose. Hidden or off-topic capabilities are dangerous because they obscure the skill’s true behavior, making review harder and creating an avenue for prompt confusion, overreach, or repurposing beyond user expectations.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The documentation claims the skill is a pure static Markdown guide with no external dependencies, yet elsewhere it advertises executable command-based behaviors and runtime operations. These contradictory statements undermine trust and can cause an agent or reviewer to underestimate the skill’s operational surface, leading to improper approval or tool enablement.

Intent-Code Divergence

Low
Confidence
80% confidence
Finding
The skill says it performs no network activity, but the error-handling section instructs users to run ping and troubleshoot firewall/proxy issues. While not a severe exploit by itself, this inconsistency can normalize unnecessary network diagnostics and weakens confidence in the claimed trust boundary of the skill.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The activation and usage guidance is broad enough that the skill could be invoked for loosely related requests without clear trigger constraints. Overly permissive scope increases the chance of accidental activation, prompt overreach, and reliance on sections of the skill that were never meant for the user’s actual task.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.