whatsapp-automation
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from external WhatsApp users through AI models and automated tools.
- Ingestion points: Incoming user messages are ingested via the
whatsAppTriggerand parsed into the workflow context inSKILL.md(e.g.,text: message.text.body). - Boundary markers: The provided chatbot flows and n8n configuration examples lack explicit delimiters or "ignore instructions" warnings to prevent the AI from following commands embedded within user input.
- Capability inventory: The skill possesses capabilities to send messages (
whatsapp_send_message), query internal data (lookup_order), and modify state through support ticket creation (create_ticket). - Sanitization: There is no evidence of input validation, filtering, or sanitization of the
message.text.bodycontent before it is interpolated into the AI response node or used to trigger automated logic.
Audit Metadata