vobiz-whatsapp

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and instruction for interacting with the Vobiz WhatsApp API. All referenced API endpoints and resources are consistent with the vendor's service offerings.
  • [SAFE]: The instructions actively promote security best practices, specifically requiring the verification of X-Webhook-Signature via HMAC-SHA256 to ensure the authenticity of inbound data.
  • [SAFE]: No hardcoded credentials, remote code execution patterns, or obfuscation techniques were detected. The mention of Meta access_token prefixes (e.g., 'EAA...') is descriptive and not a leak of actual secrets.
  • [SAFE]: While the skill processes inbound user data (message.inbound), it provides the necessary guidance (signature verification) to secure the ingestion point, and does not provide unsafe interpolation patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 07:07 AM
Security Audit — agent-trust-hub — vobiz-whatsapp