Back to skill

Security audit

Wonda

Security checks for vulnerabilities and agentic risk

Overview

This skill documents useful media workflows but also enables stealthy social-account automation and broad social posting or messaging authority.

Install only if you intentionally want an agent to use Wonda with connected social accounts and you are prepared to review every external action. Avoid the documented stealth, disposable signup, internal API, and detection-avoidance workflows; prefer official account APIs, pinned dependencies, an isolated environment, and explicit confirmation before posting, messaging, following, deleting, or accepting terms.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:124
Finding

Automatic Retrieval and Execution of Mutable Remote Skill Instructions

Content
View full analysis
# Full step-by-step guide for a skill ``` **If a skill matches** → `wonda skill get `, read it, adapt to context, execute each step. **If no skill matches** → build from scratch (Step 3). ``` ### Technical Analysis The Skill instructs the agent to retrieve additional instructions from an external service and execute each returned step. The retrieved content is not included in the audited package and can change independently after this version of `SKILL.md` has been reviewed. The instruction to “execute each step” establishes a dynamic instruction channel without: - Immutable version pinning - Content hashes or signature verification - A command allowlist - Validation against the original user request - A rule preventing remote instructions from changing safety constraints - Explicit user review and approval of the retrieved instructions Although the retrieved material is described as a content skill rather than executable software, it is consumed as authoritative agent instructions and may direct subsequent tool calls. A malicious or compromised remote skill could therefore alter the agent’s behavior without any modification to the locally audited package. ### Attack Path 1. An attacker compromises the Wonda skill service, a particular remote skill, or its publication account. 2. The attacker changes a remote skill so that it contains harmful or excessive instructions. 3. The agent follows the local requirement t ...[truncated 1053 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:33
Finding

Unpinned Third-Party Packages and Runtime Browser Downloads

Content
View full analysis
Remediation
View remediation

other

Error
Location
SKILL.md:59
Finding

Detection-Evasive Social Automation and Disposable Account Workflow

Content
View full analysis
--fields status`). 3. `wonda device launch com.instagram.android` (or `com.zhiliaoapp.musically` for TikTok). Fall back to `wonda device open-url` if you'd rather start in the web flow. 4. Loop: `wonda device screenshot > s.json` → decode the base64 PNG → read → pick an action → `tap | type | swipe | key` → screenshot again. Use `--text "SomeButtonLabel"` on `tap` before guessing coordinates; fall back to `--x --y` read off the screenshot for elements without matching text (number pickers, date spinners, etc.). 5. When the app sends a verification email, `wonda email inbox wait --timeout 120` — returns `{codes: ["483921"], links: [...]}` with the 6-digit code already extracted. `wonda device type --text ""` to feed it back. ``` Additional detection-evasion guidance includes: ```markdown # Write (uses internal API — use on secondary accounts) wonda x tweet "Hello world" ``` ```markdown - **`--browser` (Patchright):** Launches a real undetected Chrome browser, opens x.com compose, types with human-style jitter, clicks Post. ``` ```markdown - **`--browser` (Patchright):** Launches a real undetected Chrome browser, navigates to the profile, and clicks through the UI. Zero fingerprinting risk. Slower (~ ...[truncated 3213 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation explicitly promotes stealth browser posting modes, internal APIs, drift-proof anti-detection behavior, and use on secondary accounts. These details are not necessary for ordinary social publishing and instead facilitate platform evasion, automated posting, and resilient abuse of third-party services.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description says the skill is for generating media plus research and automation across multiple major social platforms, but it does not define narrow trigger phrases, excluded contexts, or negative examples. In a manifest-like file, this kind of expansive, generic description can overlap with many common user requests and increase the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
Not all commands are available to every account type:

| Tier                                        | Access                                                                                                                           |
| ------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- |
| **Anonymous** (temporary account, no login) | Media upload/download, editing (`video/edit`, `image/edit`, `audio/edit`), transcription, social publishing, scraping, analytics |
| **Free** (logged in, Basic/Free plan)       | Everything above + **generation** (`image/generate`, `video/generate`, etc.), styles, recipes, brand                             |

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill includes step-by-step account signup automation using disposable email and device-driving primitives, which materially exceeds a media-generation skill's stated purpose. This enables automated account creation and verification workflows on third-party platforms, increasing abuse potential for sockpuppet creation, spam operations, and policy evasion.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 345)May include surrounding context.

md
- `topaz-video-upscale` — Upscale video resolution (1-4x factor, supports fps conversion)
- `sync-lipsync-v2-pro` — Legacy lipsync for user-supplied video + audio pairs. Inferior to native-audio generation and almost never the right choice for new content. See the "Lip sync" section for rules.

Seedance family (DEFAULT video model, watermarks automatically removed):

- `seedance-2` — Base Seedance 2.0 (T2V/I2V, 5-15s, high=standard/basic=fast)
- `seedance-2-omni` — Multi-reference generation (images, audio refs)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This line instructs the agent to put dialogue and language into the video prompt and asserts the models generate dialogue in any language directly, but it does not preserve user choice or require confirmation of the desired language. That can lead the skill to force a locale/language decision without explicit user opt-in.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The skill instructs users to run npx patchright without pinning a version, which allows whatever package version is current at execution time to be fetched and executed. In an agent/tooling context, this creates supply-chain risk and reduces reproducibility, especially because the package is used for stealth browser automation that already operates in a sensitive area.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Claims such as 'Zero fingerprinting risk' and 'fully safe' are deceptive because they normalize and encourage risky stealth automation against third-party platforms. This lowers operator caution and can increase misuse of browser automation for spam, impersonation, or account farming while masking the real compliance and detection risks.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

This is a second instance of the same unpinned npx patchright execution pattern. Running an unpinned remote package from npm can introduce unexpected code changes or a compromised release into the execution path of the skill.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 857)May include surrounding context.

md
## Quality tiers

| Tier     | Image Model       | Resolution | Video Model              | When                                                                                           |
| -------- | ----------------- | ---------- | ------------------------ | ---------------------------------------------------------------------------------------------- |
| Standard | `nano-banana-2`   | 1K         | `seedance-2` (high, 5s)  | Default. High quality, good for iteration.                                                     |
| High     | `nano-banana-pro` | 1K         | `seedance-2` (high, 15s) | Longer duration. Also offer `sora2pro` for different style.                                    |

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 753)May include surrounding context.

md
# Read
wonda reddit chat inbox                                  # List DM conversations with latest messages
wonda reddit chat messages <room-id> -n 50               # Fetch messages from a room
wonda reddit chat all-rooms                              # List ALL joined rooms (not limited to sync window)

# Write
wonda reddit chat send <room-id> --text "Hey!"           # Send a DM (mimics browser typing behavior)

Static analysis

No suspicious patterns detected.