whatsapp-reading

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the @agentcomms/whatsapp package, which is fetched and executed via npx as detailed in the contract documentation.
  • Evidence: references/contract.md mentions npx -y @agentcomms/whatsapp@<version> status --json.
  • [COMMAND_EXECUTION]: The skill relies on executing the agent-whatsapp CLI tool to perform all operations, including syncing the local index, searching messages, and drafting replies.
  • Evidence: Multiple shell commands in SKILL.md (e.g., agent-whatsapp sync --account personal/whatsapp).
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external WhatsApp messages, captions, and group names, which serves as a potential vector for indirect prompt injection.
  • Ingestion points: Message text, captions, sender names, and group/channel metadata (referenced in SKILL.md and references/contract.md).
  • Boundary markers: The skill instructions mandate the use of <untrusted-content> delimiters to isolate external data from instructions.
  • Capability inventory: The agent can sync local databases, list chats, read message history, search message content, and generate draft links using the agent-whatsapp tool.
  • Sanitization: The skill implements detection for hidden.characters (invisible or bidirectional characters) and instructs the agent to report them rather than executing content that contains them.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — whatsapp-reading