Back to skill

Security audit

Whatsapp Style Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a local WhatsApp text-formatting guide with some overbroad wording and unnecessary exec permission, but no evidence of hidden, destructive, or data-exfiltrating behavior.

Before installing, note that the skill requests exec even though its main function is text formatting and no validation script is included. Use it for local message formatting, and avoid granting command execution unless you specifically need command-line validation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
74% confidence
Finding
The activation examples and broad scope language can cause the agent to invoke this skill in contexts that are not narrowly limited to WhatsApp formatting, increasing the chance of unintended execution paths. Because the skill allows `exec`, ambiguous triggering raises the risk that the agent may perform command-backed actions when simple text transformation was expected.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The claimed keyword coverage is excessively broad and ambiguous, which can expand the skill's operational envelope beyond its intended text-formatting purpose. In an agent environment, this increases prompt-routing and tool-selection risk, especially since the manifest permits `exec`, making misactivation more dangerous than a pure read-only skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.