skills/sinch/skills/sinch-whatsapp/Gen Agent Trust Hub

sinch-whatsapp

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements proactive security guidance regarding indirect prompt injection. It explicitly warns that inbound WhatsApp payloads contain untrusted user content and instructs the agent not to execute, evaluate, or interpolate this data into prompts.
  • [SAFE]: Credential management follows standard security protocols, instructing the use of environment variables (e.g., SINCH_KEY_SECRET, SINCH_ACCESS_TOKEN) instead of hardcoding sensitive tokens in source code or commands.
  • [SAFE]: All external communication and documentation links are limited to official vendor domains (developers.sinch.com, dashboard.sinch.com, and *.conversation.api.sinch.com).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 12:48 PM
Security Audit — agent-trust-hub — sinch-whatsapp