wacli
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill enables reading external message data from WhatsApp, which represents an attack surface for indirect prompt injection. The skill does not provide specific sanitization or boundary markers for this data processing, though it includes manual confirmation steps for outgoing messages.
- Ingestion points:
wacli messages searchandwacli synccommands inSKILL.md. - Boundary markers: Absent.
- Capability inventory: Command execution via the
wacliCLI and file system access viawacli send file. - Sanitization: Absent.
Audit Metadata