wacli
Pass
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Uses the
waclicommand-line utility for operations such as sending texts, files, and searching message history. - [EXTERNAL_DOWNLOADS]: Provides instructions to download and install the
waclibinary from the author's official GitHub repository and Homebrew tap. - [DATA_EXFILTRATION]: Accesses personal WhatsApp chat history and messages to enable searching and syncing functionality, as required by the tool's core features.
- [PROMPT_INJECTION]: Potential for indirect prompt injection via untrusted message data. Ingestion points: processes messages through search results. Boundary markers: instructions mandate explicit confirmation before sending. Capability inventory: can send messages to external recipients. Sanitization: no sanitization of incoming message content is specified.
Audit Metadata