Skills wonda-cli
๐Ÿ“ฆ

wonda-cli

Content revision r2 Critical โš™๏ธ External commands๐ŸŒ Network access๐Ÿ“ Filesystem access๐Ÿ”‘ Env variables

Create and Automate Media with Wonda CLI

Terminal agents need one workflow for media creation and social operations. This skill provides Wonda CLI guidance for generation, editing, publishing, research, and automation.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "wonda-cli" from https://skillstore.io/skills/degausai-wonda-cli.md and its manifest at https://skillstore.io/api/skills/degausai-wonda-cli/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "wonda-cli". Create a vertical product teaser from the supplied image and add animated captions.

Expected outcome:

  • Generated a five-second portrait video from the supplied image.
  • Added timed captions and preserved the original audio.
  • Saved the review file as product-teaser-review.mp4.

Using "wonda-cli". Research recent discussion about AI video tools without posting or messaging anyone.

Expected outcome:

  • Collected recent public discussions from the requested platforms.
  • Grouped recurring themes, objections, and commonly mentioned tools.
  • Prepared three content concepts with source links for review.

Using "wonda-cli". Prepare a branded launch post and wait for approval before publishing.

Expected outcome:

Prepared the media and caption draft. Publishing remains paused until the account owner approves the final post.

Security Audit

Critical
v6 โ€ข 7/23/2026 Open versioned report

Most presented static matches are false positives caused by Markdown code spans, example URLs, and documented local paths. Confirmed findings cover executable credential workflows and proxy-based anti-abuse evasion; semantic review also found moderation bypass, default cookie export, mutable remote instructions, unpinned installation, and credential exposure. The scanner capped review at 400 of 654 matches, so 254 lower-priority matches still require manual review before publication. Static review was capped at 400/654 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

1
Files scanned
1,944
Lines analyzed
2
Review items
0
False positives ignored

Confirmed security concerns (8)

Critical
[HEURISTIC] DANGEROUS COMBINATION: Code execution + Network + Credential access
This combination is common in credential stealers and RATs
The skill directs agents to install and execute an external CLI, retrieve decrypted credentials, and transmit browser cookies. This confirms the dangerous capability combination, although the behavior is disclosed rather than obfuscated.
Critical
Provider Moderation Bypass for Real-Person Cloning
The guide recommends switching to Kling when another provider blocks a real-person reference, specifically because the raw face audio avoids a moderation classifier. This enables impersonation and non-consensual likeness or voice cloning.
The text explicitly names the blocked real-person condition, the alternate provider, and avoidance of the moderation classifier.
High
[HEURISTIC] SUSPICIOUS COMBINATION: Filesystem + Credentials + Network
This combination could indicate credential harvesting and exfiltration
The skill stores platform cookies on disk and states that synchronized cookie JSON is automatically pushed to the Wonda backend. Filesystem, credential, and network capabilities are therefore combined in a security-sensitive workflow.
High
Automatic Cloud Upload of Browser Session Cookies
Cookie cloud backup is enabled by default and pushes synchronized platform cookie JSON to Wonda. The document states the wire payload is plaintext and server storage can be plaintext when its encryption key is absent.
The default, transfer destination, payload format, and conditional at-rest encryption are all explicitly documented.
High
Platform Anti-Abuse Evasion and Synthetic Account Automation
The skill uses an antidetect browser, throwaway email, residential proxies, human-like motion, and varied messages to create accounts and avoid detection. It also automates engagement and outreach.
The guide repeatedly states anti-fingerprinting and shadowban-avoidance goals and provides complete account-creation and engagement workflows.
High
Mutable Remote Instructions Executed Without Pinning
The guide requires agents to pull account-editable skills live from Wonda and execute each step. It provides no content hash, signature verification, approval boundary, or prompt-injection review before execution.
Remote mutability and direct execution are explicit, while no integrity or trust-control step is documented in the reviewed skill.
High
Unpinned Global Installation of Executable Packages
The setup directs agents to install the latest npm package globally or trust a Homebrew tap without a version, checksum, or signature verification step. A compromised upstream release would gain local execution.
Both installation commands are explicit and unpinned, and neither path includes an integrity verification step.
High
Credential Exposure Through Agent Output and Arguments
The guide permits agents to retrieve decrypted passwords and pass passwords in command arguments. Account-creation flows also print passwords in success output, exposing secrets to process listings, shell history, transcripts, or logs.
The reviewed commands and prose explicitly describe decrypted retrieval, password arguments, and password-bearing success output.
Capability review items (2)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
SOCKS proxy
**LinkedIn account creation:** `wonda linkedin signup` provisions a brand-new LinkedIn account: it m
This section recommends a mobile or residential SOCKS proxy when creating a new social account to avoid platform shadowbans. The proxy is explicitly used for anti-abuse evasion.
High
SOCKS proxy
`wonda reddit signup` provisions a brand-new Reddit account: it mints a throwaway mailbox (or uses `
This section recommends a mobile or residential SOCKS proxy when creating a new social account to avoid platform shadowbans. The proxy is explicitly used for anti-abuse evasion.

Risk Factors

โš™๏ธ External commands (50)
๐ŸŒ Network access (32)
๐Ÿ“ Filesystem access (49)
๐Ÿ”‘ Env variables (4)

Detected Patterns

[HEURISTIC] DANGEROUS COMBINATION: Code execution + Network + Credential access
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/degausai-wonda-cli/audits/6?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/degausai-wonda-cli/security.svg)](https://skillstore.io/skills/degausai-wonda-cli?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/degausai-wonda-cli?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/degausai-wonda-cli/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/degausai-wonda-cli.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

degausai. (2026). wonda-cli security audit report (audit version 6) [Author version unspecified]. Skillstore. https://skillstore.io/skills/degausai-wonda-cli/audits/6

BibTeX citation

@techreport{degausai-degausai-wonda-cli-2026, author = {degausai}, title = {wonda-cli security audit report (audit version 6)}, institution = {Skillstore}, year = {2026}, number = {6}, url = {https://skillstore.io/skills/degausai-wonda-cli/audits/6}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "wonda-cli security audit report (audit version 6)" version: "unspecified" type: report authors: - name: "degausai" date-released: "2026-07-23" url: "https://skillstore.io/skills/degausai-wonda-cli/audits/6" identifiers: - type: other value: "skillstore:degausai-wonda-cli:audit:6" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
69
Community
70
Spec Compliance

What You Can Build

Produce Campaign Media

Generate branded images, short videos, narration, captions, and final delivery files through a guided workflow.

Research Social Conversations

Collect relevant posts, profiles, comments, and engagement signals before drafting a content plan.

Operate Approved Publishing Workflows

Prepare, review, publish, and monitor content across connected accounts with explicit approval before writes.

Try These Prompts

Generate One Image
Create an image of [subject] for [channel]. Use [aspect ratio] and save the final image to [path].
Finish a Video Locally
Inspect [video path]. Trim it to [duration], add [caption style], preserve the source audio, and export a review copy.
Research Before Drafting
Research [topic] on [platforms] using read-only commands. Summarize themes, cite source URLs, and propose three content concepts without publishing.
Run a Controlled Campaign Workflow
Build a campaign for [brand] using [assets]. Estimate cost first, generate drafts, request approval, then publish only approved items to [accounts].

Best Practices

  • Confirm costs, target accounts, and publishing scope before starting remote jobs or social writes.
  • Use browser login, least-privilege credentials, dry runs, and explicit approval for sensitive account operations.
  • Keep deterministic media finishing local and inspect every generated asset before publication.

Avoid

  • Do not paste passwords, API keys, session cookies, or private messages into prompts or logs.
  • Do not automate account creation, bulk outreach, engagement, or moderation bypasses.
  • Do not execute mutable remote skills or unpinned packages without reviewing their source and integrity.

Frequently Asked Questions

Does this skill work without a Wonda account?
Some local commands work without an account. Generation, scraping, publishing, and cloud features require a paid account.
Which local tools are required?
Requirements vary by workflow. Media editing commonly needs Node, ffmpeg, ffprobe, and bundled Chromium.
Can it publish directly to social platforms?
Yes, for supported connected accounts. Review the media, text, target account, privacy settings, and platform rules before publishing.
Where are authentication details stored?
The CLI can use environment keys, local cookie stores, browser profiles, a credentials vault, and optional cloud session storage.
Can it run social actions automatically?
The CLI supports browser, relay, schedule, and cloud-twin actions. These features require explicit authorization and careful policy review.
Are generated outputs always safe to publish?
No. Review rights, consent, likeness, accuracy, platform policy, brand standards, and disclosure requirements before publication.

Developer Details

Author

degausai

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

c43861a65bb95efcae259cd161c9d6f4dc7eec6f

Maintenance freshness

7/25/2026

Usage

3 downloads ยท 121 views

File structure

๐Ÿ“„ SKILL.md

View all