whatsapp-telegram

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes scripts/verify.sh, a local utility script designed for static analysis of integration code. It uses standard shell tools like find and grep to detect hardcoded secrets and configuration errors without performing any external network operations or executing untrusted code.
  • [EXTERNAL_DOWNLOADS]: The skill correctly references official communication endpoints for established services, including Meta's Graph API (graph.facebook.com) and Telegram's Bot API (api.telegram.org).
  • [INDIRECT_PROMPT_INJECTION]: The skill documentation addresses the ingestion of external data from webhooks and provides patterns for securing these interactions. Evidence chain: (1) Ingestion points: Inbound message payloads received via webhooks (e.g., references/whatsapp-cloud-api.md); (2) Boundary markers: Detailed instructions for verifying X-Hub-Signature-256 HMAC signatures; (3) Capability inventory: The skill documents outbound messaging via fetch and curl commands in SKILL.md; (4) Sanitization: The reference documentation (references/telegram-bot-api.md) provides specific guidance on escaping reserved characters for MarkdownV2 and utilizing HTML parsing for safer message handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:57 AM
Security Audit — agent-trust-hub — whatsapp-telegram