Observe Whatsapp
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a suite of Node.js scripts (e.g.,
messages.js,api-logs.js,whatsapp-health.js) for the agent to execute. These scripts are used for operational diagnostics such as inspecting message details, triaging API errors, and checking health status.- [EXTERNAL_DOWNLOADS]: The instructions include a requirement to runnpm ito install project dependencies from the NPM registry.- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves processing external data such as WhatsApp messages and logs. This creates a surface for indirect prompt injection if the ingested data contains malicious instructions. However, this is an inherent aspect of monitoring and troubleshooting tools. - Ingestion points: External data is fetched from the Kapso API by scripts in the
scripts/directory. - Boundary markers: The instructions do not define specific delimiters for separating data from instructions.
- Capability inventory: The skill allows script execution to interact with the vendor's API.
- Sanitization: Not explicitly documented in the instruction markdown.
Audit Metadata