agent-whatsappbot
Fail
Audited by Snyk on May 8, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt's examples and commands require passing an access token as a command-line argument (agent-whatsappbot auth set ) and show a config field "access_token", which forces the agent to include secret values verbatim in generated commands or config—an exfiltration risk.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata