observe-whatsapp

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill does not exhibit any malicious patterns. It is designed for operational diagnostics and uses standard authentication and communication methods.
  • [EXTERNAL_DOWNLOADS]: The openapi-explore.mjs script retrieves OpenAPI specifications from the vendor's documentation site at docs.kapso.ai to facilitate API exploration.
  • [DATA_EXFILTRATION]: The skill interacts with the Kapso platform API using credentials provided through environment variables. These operations are restricted to the intended platform endpoints.
  • [PROMPT_INJECTION]: The skill processes data from the WhatsApp API, such as message logs and error details. This constitutes an ingestion point for external content, which could serve as a surface for indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 01:53 AM