integrate-whatsapp

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill instructions and associated scripts are focused on legitimate integration with the Kapso WhatsApp platform. No evidence of prompt injection, obfuscation, or unauthorized data access was found.\n- [EXTERNAL_DOWNLOADS]: The openapi-explore.mjs utility fetches OpenAPI specifications from docs.kapso.ai. These downloads are used to provide the agent with technical context about the Kapso API and are retrieved from the vendor's official documentation domain.\n- [COMMAND_EXECUTION]: The skill includes a variety of Node.js scripts that wrap API calls to api.kapso.ai and the Meta WhatsApp proxy. These scripts automate tasks such as creating templates, managing WhatsApp Flows, and configuring webhooks. All operations are documented and serve the primary purpose of the skill.\n- [SAFE]: The skill enables the deployment of custom code to the Kapso platform (e.g., Kapso Functions). While this involves remote code deployment, the scripts are designed as administrative tools for the user to manage their own cloud resources on the vendor's platform. The skill also processes external data from WhatsApp webhooks but includes documentation on signature verification to ensure data integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 11:35 PM