Automate Whatsapp

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external triggers and data from WhatsApp and app integrations, creating a potential surface for indirect prompt injection where malicious content in processed data could attempt to influence the agent's logic. \n
  • Ingestion points: WhatsApp message triggers, database row queries (query-rows.js), and integration responses. \n
  • Boundary markers: None identified in the provided instructions to separate untrusted data from agent context. \n
  • Capability inventory: Deploying and invoking serverless functions (deploy-function.js), database CRUD operations, and workflow graph management. \n
  • Sanitization: No explicit sanitization or validation logic is outlined for external data. \n- [DYNAMIC_EXECUTION]: The skill facilitates the creation, update, and deployment of serverless functions to a remote runtime environment via scripts such as create-function.js and deploy-function.js. \n- [COMMAND_EXECUTION]: The skill's operation relies on the execution of numerous local Node.js scripts to manage project components via the platform API. \n- [METADATA_POISONING]: The skill frontmatter includes a risk: safe field, which is a self-referential claim that should not be used as an authoritative assessment of the skill's safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 01:26 PM
Security Audit — agent-trust-hub — Automate Whatsapp