evolution-api

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill documents an interface for receiving and processing WhatsApp messages, which constitutes an indirect prompt injection surface.
  • Ingestion points: Incoming WhatsApp messages are ingested via webhooks (e.g., MESSAGES_UPSERT) as described in SKILL.md and references/events.md.
  • Boundary markers: There are no instructions or patterns provided to delimit untrusted message content from agent instructions.
  • Capability inventory: The API supports extensive capabilities including sending messages (text, media, audio), managing groups (adding/removing participants), updating profile settings, and triggering external automation workflows via n8n or OpenAI integrations (api-endpoints.md).
  • Sanitization: The documentation does not define any sanitization, filtering, or validation steps for incoming message data before it is passed to integrated services or processed by the agent.
  • [NO_CODE]: The skill consists entirely of markdown documentation and configuration references. No executable scripts (Python, JavaScript, Shell) are included in the skill package.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:05 AM
Security Audit — agent-trust-hub — evolution-api