waba-embedded-signup
Plan Secure WABA Embedded Signup
WABA onboarding can mix incompatible signup paths, credentials, and callback contracts. This skill guides secure Sent profile setup, verification, testing, and failure recovery.
自分のエージェントでインストール
このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。
Review the Skillstore skill "waba-embedded-signup" from https://skillstore.io/skills/sentdm-waba-embedded-signup.md and its manifest at https://skillstore.io/api/skills/sentdm-waba-embedded-signup/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。
エージェントが読めるリソース
AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。
テストする
「waba-embedded-signup」を使用しています。 Our organization has no connected WABA, and a child should share one.
期待される結果:
- Start with organization Embedded Signup in the Sent dashboard.
- Confirm the organization WABA connection before creating the child.
- Create the child without dedicated WABA credentials.
- Validate tenant boundaries, mapping, completion, and callback delivery.
「waba-embedded-signup」を使用しています。 A dedicated child profile remains submitted after completion returned 202.
期待される結果:
Treat 202 as processing confirmation. Check prerequisites and verified callback evidence, preserve unknown statuses, and avoid declaring failure prematurely.
「waba-embedded-signup」を使用しています。 A profile key receives 403 while using the child-profile header.
期待される結果:
Remove the child-profile header when using a profile key. Use an authorized organization key only when operating across an existing child profile.
セキュリティ監査
安全All 38 static alerts are false positives caused by Markdown formatting, documented identifiers, a reserved example URL, and defensive readiness guidance. No executable commands, reconnaissance behavior, prompt injection, or malicious intent were found.
リスク要因
⚙️ 外部コマンド (28)
🌐 ネットワークアクセス (1)
このレポートを共有・引用
バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。
レポートリンクをコピー
https://skillstore.io/skills/sentdm-waba-embedded-signup/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdownバッジ
[](https://skillstore.io/skills/sentdm-waba-embedded-signup?utm_source=security_passport_badge)HTMLバッジ
<a href="https://skillstore.io/skills/sentdm-waba-embedded-signup?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sentdm-waba-embedded-signup/security.svg" alt="Skillstore security assessment" loading="lazy"></a>埋め込みカード
<iframe src="https://skillstore.io/embed/skills/sentdm-waba-embedded-signup.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>学術引用 (APA · BibTeX · CFF)
APA形式の引用
sentdm. (2026). waba-embedded-signup security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sentdm-waba-embedded-signup/audits/1BibTeX形式の引用
@techreport{sentdm-sentdm-waba-embedded-signup-2026,
author = {sentdm},
title = {waba-embedded-signup security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/sentdm-waba-embedded-signup/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "waba-embedded-signup security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "sentdm"
date-released: "2026-09-02"
url: "https://skillstore.io/skills/sentdm-waba-embedded-signup/audits/1"
identifiers:
- type: other
value: "skillstore:sentdm-waba-embedded-signup:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore スコア
このスコアの理由 証拠の信頼度: 中作成できるもの
Design Organization Onboarding
Choose dashboard signup or shared WABA inheritance, then document prerequisites, tenant boundaries, and launch checks.
Implement Dedicated Profiles
Prepare secure child-profile creation, credential handling, number mapping, completion callbacks, and sandbox testing.
Resolve Onboarding Failures
Diagnose authorization errors, missing WABA prerequisites, incorrect mappings, expired tokens, and incomplete callbacks.
これらのプロンプトを試す
Explain which Sent WABA onboarding path fits an organization needing its first account. Include prerequisites and safe next steps.
Create a checklist for a child profile inheriting the organization WABA. Cover authentication, sandbox testing, completion, and callbacks.
Review this dedicated WABA onboarding design: [design]. Identify credential, tenant mapping, callback, status, and rollback risks.
Develop a runbook for [tenant model]. Compare paths, define records, route failures, preserve audit evidence, and set launch gates.
ベストプラクティス
- Select the onboarding path before designing requests or credential storage.
- Inject tokens server-side, redact logs, and retain only secret-manager references.
- Test in sandbox and verify mappings, callback authenticity, idempotency, and tenant attribution.
回避
- Do not invent a public Sent endpoint for hosted Embedded Signup.
- Do not expose WABA tokens through browsers, logs, fixtures, errors, or support output.
- Do not treat profile completion, Meta browser messages, and message webhooks as one event contract.
よくある質問
Can this skill start Embedded Signup?
When should a child inherit the organization WABA?
Which dedicated WABA fields are required?
How should access tokens be handled?
Does a 202 response mean completion succeeded?
Can a profile key use the child-profile header?
開発者情報
作成者
sentdmライセンス
MIT
Skillstore リビジョン
r1
バージョンに関する注意
作者はバージョンを宣言していません。
参照
096c7daa4d0d974771dad12d81c3d0d4688617b9
メンテナンスの新しさ
2026/9/8
利用状況
1 ダウンロード · 0 閲覧