whatsapp-automation

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from external WhatsApp users through AI models and automated tools.
  • Ingestion points: Incoming user messages are ingested via the whatsAppTrigger and parsed into the workflow context in SKILL.md (e.g., text: message.text.body).
  • Boundary markers: The provided chatbot flows and n8n configuration examples lack explicit delimiters or "ignore instructions" warnings to prevent the AI from following commands embedded within user input.
  • Capability inventory: The skill possesses capabilities to send messages (whatsapp_send_message), query internal data (lookup_order), and modify state through support ticket creation (create_ticket).
  • Sanitization: There is no evidence of input validation, filtering, or sanitization of the message.text.body content before it is interpolated into the AI response node or used to trigger automated logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:30 PM
Security Audit — agent-trust-hub — whatsapp-automation