whatsapp-telegram
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes
scripts/verify.sh, a local utility script designed for static analysis of integration code. It uses standard shell tools likefindandgrepto detect hardcoded secrets and configuration errors without performing any external network operations or executing untrusted code. - [EXTERNAL_DOWNLOADS]: The skill correctly references official communication endpoints for established services, including Meta's Graph API (
graph.facebook.com) and Telegram's Bot API (api.telegram.org). - [INDIRECT_PROMPT_INJECTION]: The skill documentation addresses the ingestion of external data from webhooks and provides patterns for securing these interactions. Evidence chain: (1) Ingestion points: Inbound message payloads received via webhooks (e.g.,
references/whatsapp-cloud-api.md); (2) Boundary markers: Detailed instructions for verifyingX-Hub-Signature-256HMAC signatures; (3) Capability inventory: The skill documents outbound messaging viafetchandcurlcommands inSKILL.md; (4) Sanitization: The reference documentation (references/telegram-bot-api.md) provides specific guidance on escaping reserved characters for MarkdownV2 and utilizing HTML parsing for safer message handling.
Audit Metadata