Back to skill

Security audit

Wdh

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed paid WDH.sh CLI helper, with real-money wallet use and public publishing behavior that users should handle carefully.

Use a dedicated low-balance Base wallet, assume each CLI run may spend USDC, and review content before uploading or publishing because generated links can be public and some short links do not expire by default.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger guidance includes generic terms like 'USDC', 'micropayment', 'pay-per-call', and 'EVM wallet', which can cause the skill to be invoked in conversations that are only loosely related to WDH.sh. Because every invocation may lead to a paid action tied to a wallet private key, overbroad triggering increases the chance of unintended spending or use of the wrong tool.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill describes file uploads, URL shortening, markdown publishing, and QR generation without prominently warning that several outputs are publicly accessible, including expiring public file URLs, hosted markdown pages, and potentially permanent short links. A user or agent may unintentionally publish sensitive data, creating confidentiality and privacy exposure that can persist beyond the immediate session.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
Although the skill mentions that commands 'pay automatically' and that the wallet key is required, it does not present a strong, explicit safety warning that every CLI call will automatically sign and spend from the configured wallet. In an agent context, this can lead to users underestimating financial consequences, especially when retries, duplicate submissions, or accidental invocation can trigger real charges.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.