Back to skill

Security audit

WhatsApp样式工具-免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is a local WhatsApp text-formatting guide with minor documentation inconsistencies but no artifact-backed harmful behavior.

Safe to install for formatting WhatsApp messages, but treat it as a text-processing helper: avoid providing sensitive message content unless you trust the host agent, and do not use callback_url-style workflows unless the publisher clarifies the data flow.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill claims local-only processing while also documenting a `callback_url` for asynchronous notifications, which implies potential outbound network communication. This mismatch can mislead users and host agents about the skill’s trust boundary, causing sensitive message content or metadata to be sent externally when users expect strictly local handling.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documentation states the skill performs pure local processing with no network requests, yet elsewhere it includes callback behavior and network troubleshooting guidance such as connectivity and firewall checks. These contradictory statements undermine security transparency and may cause users to expose content in environments where outbound access should be prohibited.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill is invoked through broad natural-language phrasing rather than narrowly scoped commands, increasing the chance it will activate on unrelated user requests. In an agent context with `read`, `write`, and especially `exec` tools declared, ambiguous triggering can lead to unintended processing or tool use beyond what the user explicitly requested.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.