Back to skill

Security audit

WhatsApp 排版入门

Security checks for vulnerabilities and agentic risk

Overview

This looks like a simple WhatsApp formatting guide, but its documentation also claims unrelated file-writing, API, and command-execution capabilities.

Review carefully before installing. The artifact does not include executable code and only declares read access, but its instructions are inconsistent and overstate capabilities; install only if you are comfortable treating it strictly as a text-formatting reference and ignoring the unrelated command, file-write, API, and security-control sections.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill is presented as a simple WhatsApp formatting guide, but later sections claim broad automation, file parsing, API integration, and command execution capabilities unrelated to that purpose. This kind of scope inflation can mislead an agent or operator into granting trust or using the skill in contexts far beyond its declared function, increasing the chance of unsafe tool use and policy bypass through deceptive documentation.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Introducing command execution behavior in the error-handling section is unjustified for a guide-only skill and can normalize unsafe operational actions that users or agents may attempt to follow. Even if the declared tool set is limited, the documentation creates dangerous confusion about expected behavior and can encourage privilege expansion or unsafe manual execution.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The security section discusses API keys, HTTPS, command whitelisting, and related controls that do not fit a pure Markdown WhatsApp styling guide. This mismatch can falsely imply the skill legitimately handles secrets, networking, or command execution, which broadens perceived authority and may cause operators to overtrust or misconfigure the skill.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The document explicitly states it is pure Markdown with no exec capability, yet later claims command execution and operational command workflows. Internal contradictions about capability boundaries are dangerous because they obscure what the skill may cause an agent or user to do, undermining trust and making hidden overreach harder to detect.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The skill says it does not involve WhatsApp API calls, but later advertises API integration and external service invocation. This contradiction is risky because it misrepresents the trust boundary of the skill and may lead reviewers or agents to overlook latent attempts to expand functionality beyond the declared purpose.

Static analysis

No suspicious patterns detected.