Automate Whatsapp
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external triggers and data from WhatsApp and app integrations, creating a potential surface for indirect prompt injection where malicious content in processed data could attempt to influence the agent's logic. \n
- Ingestion points: WhatsApp message triggers, database row queries (
query-rows.js), and integration responses. \n - Boundary markers: None identified in the provided instructions to separate untrusted data from agent context. \n
- Capability inventory: Deploying and invoking serverless functions (
deploy-function.js), database CRUD operations, and workflow graph management. \n - Sanitization: No explicit sanitization or validation logic is outlined for external data. \n- [DYNAMIC_EXECUTION]: The skill facilitates the creation, update, and deployment of serverless functions to a remote runtime environment via scripts such as
create-function.jsanddeploy-function.js. \n- [COMMAND_EXECUTION]: The skill's operation relies on the execution of numerous local Node.js scripts to manage project components via the platform API. \n- [METADATA_POISONING]: The skill frontmatter includes arisk: safefield, which is a self-referential claim that should not be used as an authoritative assessment of the skill's safety.
Audit Metadata