Pass
Audited by Gen Agent Trust Hub on Mar 1, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses standard 'curl' and 'jq' commands to send messages and process API responses.
- [EXTERNAL_DOWNLOADS]: All network operations are directed to 'graph.facebook.com', the official and well-known domain for Meta's WhatsApp Business API.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials or secrets were found. The skill correctly prompts for the use of environment variables 'WHATSAPP_ACCESS_TOKEN' and 'WHATSAPP_PHONE_ID'.
Audit Metadata