Back to plugin

Security audit

WhatsApp

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent WhatsApp channel plugin that discloses its WhatsApp login, messaging, media, history/search helper, and optional call capabilities.

Install only if you want OpenClaw connected to a WhatsApp account. Use a separate WhatsApp number if possible, keep allowlists and pairing policies tight, and only enable wacli history sync, plugin message hooks, or voice calls when you understand that they expose private WhatsApp content or use a separate linked-device session.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
node_modules/baileys/lib/Utils/messages-media.js:88
Evidence
exec(cmd, err => {

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
node_modules/baileys/node_modules/pino/benchmarks/utils/generate-benchmark-doc.js:7
Evidence
return execSync(`node ${join(__dirname, 'runbench')} ${type} -q`)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
node_modules/baileys/node_modules/pino/benchmarks/utils/runbench.js:75
Evidence
const benchmark = spawn(

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
node_modules/baileys/node_modules/pino/test/pkg/pkg.test.js:29
Evidence
const { stderr } = await execFile('npx', ['pkg', filePath, '--config', configPath], { shell: true })

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
node_modules/baileys/node_modules/process-warning/test/no-warnings.test.js:11
Evidence
const child = spawnSync(process.execPath, [

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
node_modules/baileys/node_modules/thread-stream/test/pkg/pkg.test.js:19
Evidence
const { stderr } = await exec(`npx pkg ${filePath} --config ${configPath}`)

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/baileys/node_modules/pino/test/esm/index.test.js:15
Evidence
new Function('module', 'return import(module)')('./esm.mjs').catch((err) => {

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/baileys/node_modules/pino/test/fixtures/eval/index.js:3
Evidence
eval(`

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
node_modules/baileys/node_modules/real-require/src/index.js:4
Evidence
const realImport = new Function('modulePath', 'return import(modulePath)')

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
node_modules/baileys/node_modules/@pinojs/redact/test/actual-redact-comparison.test.js:126
Evidence
password: '[REDACTED]'

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
node_modules/baileys/node_modules/@pinojs/redact/test/multiple-wildcards.test.js:204
Evidence
authorization: '[REDACTED]'