whatsapp-reading
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the
@agentcomms/whatsapppackage, which is fetched and executed vianpxas detailed in the contract documentation. - Evidence:
references/contract.mdmentionsnpx -y @agentcomms/whatsapp@<version> status --json. - [COMMAND_EXECUTION]: The skill relies on executing the
agent-whatsappCLI tool to perform all operations, including syncing the local index, searching messages, and drafting replies. - Evidence: Multiple shell commands in
SKILL.md(e.g.,agent-whatsapp sync --account personal/whatsapp). - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external WhatsApp messages, captions, and group names, which serves as a potential vector for indirect prompt injection.
- Ingestion points: Message text, captions, sender names, and group/channel metadata (referenced in
SKILL.mdandreferences/contract.md). - Boundary markers: The skill instructions mandate the use of
<untrusted-content>delimiters to isolate external data from instructions. - Capability inventory: The agent can sync local databases, list chats, read message history, search message content, and generate draft links using the
agent-whatsapptool. - Sanitization: The skill implements detection for
hidden.characters(invisible or bidirectional characters) and instructs the agent to report them rather than executing content that contains them.
Audit Metadata