sinch-whatsapp
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements proactive security guidance regarding indirect prompt injection. It explicitly warns that inbound WhatsApp payloads contain untrusted user content and instructs the agent not to execute, evaluate, or interpolate this data into prompts.
- [SAFE]: Credential management follows standard security protocols, instructing the use of environment variables (e.g.,
SINCH_KEY_SECRET,SINCH_ACCESS_TOKEN) instead of hardcoding sensitive tokens in source code or commands. - [SAFE]: All external communication and documentation links are limited to official vendor domains (
developers.sinch.com,dashboard.sinch.com, and*.conversation.api.sinch.com).
Audit Metadata