whatsapp-automation

Warn

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The instructions require the user to add an external MCP server endpoint (https://rube.app/mcp) to their agent configuration. This domain is not associated with a trusted vendor, and connecting to unverified third-party MCP servers allows that server to execute code on behalf of the agent and process all tool-related data.
  • [DATA_EXFILTRATION]: By design, the skill transmits potentially sensitive business information, including messages, contact details, and media, through the configured rube.app endpoint. The claim that 'No API keys needed' suggests the server manages authentication centrally, which may involve the interception or storage of communication tokens and message content.
  • [PROMPT_INJECTION]: The skill processes external, untrusted data from incoming WhatsApp messages to facilitate replies (WHATSAPP_SEND_REPLY).
  • Ingestion points: Incoming message content processed by the agent to generate replies (SKILL.md).
  • Boundary markers: None identified in the provided instructions to differentiate between system instructions and content from WhatsApp messages.
  • Capability inventory: The skill possesses capabilities to send messages, upload media, and share contacts, which could be abused if an incoming message successfully injects instructions.
  • Sanitization: No evidence of sanitization or filtering of incoming message content before it enters the agent's context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 3, 2026, 05:35 PM
Security Audit — agent-trust-hub — whatsapp-automation