All skills
aws avatar

/aws-social-messaging

@6329aa8

Manages WhatsApp messaging through AWS End User Messaging Social. Covers managing templates (create, update, delete, library), sending messages (utility/marketing/auth templates and freeform), uploading and managing media, configuring event destinations for delivery tracking, and troubleshooting delivery failures. Applicable when a user needs to send WhatsApp messages, create or manage templates, upload media, configure delivery notifications, or diagnose messaging issues.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-social-messaging

This session only. Nothing lands on disk.

referencesconfiguring-event-destinations.md

≈992 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Configuring Event Destinations

Security: Encrypt SNS topics with KMS; callbacks may contain recipient metadata. See SKILL.md — Security Considerations.

Contents

Overview

Event destinations deliver real-time notifications for:

  • Message delivery status (sent, delivered, read, failed)
  • Template status changes (approved, rejected)
  • Template reclassification (UTILITY → MARKETING)

Without event destinations, delivery failures and reclassifications are invisible.

Configure Event Destination

A WABA can only have one event destination at a time.

aws socialmessaging put-whatsapp-business-account-event-destinations \
  --id "waba-XXXXXXXXXXXXXXXXXXXX" \
  --event-destinations '[{"eventDestinationArn":"arn:aws:sns:us-east-1:123456789012:whatsapp-events","roleArn":"arn:aws:iam::123456789012:role/WhatsAppEventDeliveryRole"}]'

Parameters

Parameter Required Description
--id Yes WABA ID (format: waba-XXXX)
--event-destinations Yes Array with one entry: SNS topic ARN + IAM role ARN

Prerequisites

1. SNS Topic

Create an SNS topic with KMS encryption:

aws sns create-topic --name whatsapp-events --attributes '{"KmsMasterKeyId":"alias/aws/sns"}'

2. IAM Role

The role must:

  • Trust social-messaging.amazonaws.com in its assume-role policy
  • Have sns:Publish permission on the SNS topic

Trust policy:

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Principal": {"Service": "social-messaging.amazonaws.com"},
    "Action": "sts:AssumeRole",
    "Condition": {
      "StringEquals": {"aws:SourceAccount": "123456789012"},
      "ArnLike": {"aws:SourceArn": "arn:aws:social-messaging:*:123456789012:*"}
    }
  }]
}

Permission policy (attach to the role):

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": "sns:Publish",
    "Resource": "arn:aws:sns:us-east-1:123456789012:whatsapp-events"
  }]
}

3. SNS Topic Policy

Add a resource policy to allow social-messaging.amazonaws.com to publish, with condition keys to prevent confused deputy:

{
  "Version": "2012-10-17",
  "Statement": [{
    "Sid": "AllowSocialMessagingPublish",
    "Effect": "Allow",
    "Principal": {"Service": "social-messaging.amazonaws.com"},
    "Action": "sns:Publish",
    "Resource": "arn:aws:sns:us-east-1:123456789012:whatsapp-events",
    "Condition": {
      "StringEquals": {"aws:SourceAccount": "123456789012"},
      "ArnLike": {"aws:SourceArn": "arn:aws:social-messaging:*:123456789012:*"}
    }
  },
  {
    "Sid": "DenyNonSSL",
    "Effect": "Deny",
    "Principal": "*",
    "Action": "sns:Publish",
    "Resource": "arn:aws:sns:us-east-1:123456789012:whatsapp-events",
    "Condition": {
      "Bool": {"aws:SecureTransport": "false"}
    }
  }]
}

Verify Configuration

Check SNS subscriptions are confirmed:

aws sns list-subscriptions-by-topic \
  --topic-arn "arn:aws:sns:us-east-1:123456789012:whatsapp-events"

Subscriptions must show "SubscriptionArn" (not "PendingConfirmation").

Verify SNS subscription endpoints are authorized personnel/systems — use access policies to restrict who can subscribe. Use HTTPS-only endpoints for encryption in transit.

Event Payload Examples

Delivery receipt:

{
  "eventType": "MESSAGE_STATUS_UPDATE",
  "messageId": "wamid.XXXX",
  "status": "delivered",
  "recipientId": "+14155551234"
}

Template reclassification:

{
  "eventType": "TEMPLATE_STATUS_UPDATE",
  "templateName": "order_update",
  "previousCategory": "UTILITY",
  "newCategory": "MARKETING"
}

Source: SKILL.md on GitHub

No alerts1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a comprehensive and secure framework for managing WhatsApp messaging through AWS services. It includes security considerations such as the requirement for specific IAM permissions and the handling of recipient data. While these warrant review, they are implemented using standard AWS security controls like least-privilege policies and KMS encryption, aligning with the skill's intended functionality. See detailed analysis for context.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 6329aa8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/aws-social-messaging