Back to skill

Security audit

wan

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent RunAPI Wan video-generation helper that discloses its authentication, network use, paid task submission, file upload, and local output behavior.

Before installing, users should understand that this skill can submit RunAPI jobs that may incur cost, upload referenced local media to the service, and rely on an API key or saved CLI authentication; keep control of which files are referenced in requests and review task responses before treating outputs as complete.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.