skills/steipete/openclaw/wacli/Gen Agent Trust Hub

wacli

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the wacli tool from the author's GitHub repository and Homebrew tap. These sources are associated with the skill author.
  • [COMMAND_EXECUTION]: Uses the wacli CLI for WhatsApp operations such as searching messages, backfilling history, and sending files or text.
  • [PROMPT_INJECTION]: The skill processes untrusted content from WhatsApp messages, creating a surface for indirect prompt injection.
  • Ingestion points: SKILL.md (via commands that search or list chat history).
  • Boundary markers: None specified for the agent to use when interpreting message data.
  • Capability inventory: SKILL.md (send message, send file, auth/sync).
  • Sanitization: No explicit content filtering is implemented for external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 02:11 PM
Security Audit — agent-trust-hub — wacli