Terminal agents need one workflow for media creation and social operations. This skill provides Wonda CLI guidance for generation, editing, publishing, research, and automation.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Agent request
Review the Skillstore skill "wonda-cli" from https://skillstore.io/skills/degausai-wonda-cli.md and its manifest at https://skillstore.io/api/skills/degausai-wonda-cli/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.
Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Most presented static matches are false positives caused by Markdown code spans, example URLs, and documented local paths. Confirmed findings cover executable credential workflows and proxy-based anti-abuse evasion; semantic review also found moderation bypass, default cookie export, mutable remote instructions, unpinned installation, and credential exposure. The scanner capped review at 400 of 654 matches, so 254 lower-priority matches still require manual review before publication. Static review was capped at 400/654 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
This combination is common in credential stealers and RATs
The skill directs agents to install and execute an external CLI, retrieve decrypted credentials, and transmit browser cookies. This confirms the dangerous capability combination, although the behavior is disclosed rather than obfuscated.
Provider Moderation Bypass for Real-Person Cloning
The guide recommends switching to Kling when another provider blocks a real-person reference, specifically because the raw face audio avoids a moderation classifier. This enables impersonation and non-consensual likeness or voice cloning.
The text explicitly names the blocked real-person condition, the alternate provider, and avoidance of the moderation classifier.
This combination could indicate credential harvesting and exfiltration
The skill stores platform cookies on disk and states that synchronized cookie JSON is automatically pushed to the Wonda backend. Filesystem, credential, and network capabilities are therefore combined in a security-sensitive workflow.
Cookie cloud backup is enabled by default and pushes synchronized platform cookie JSON to Wonda. The document states the wire payload is plaintext and server storage can be plaintext when its encryption key is absent.
The default, transfer destination, payload format, and conditional at-rest encryption are all explicitly documented.
Platform Anti-Abuse Evasion and Synthetic Account Automation
The skill uses an antidetect browser, throwaway email, residential proxies, human-like motion, and varied messages to create accounts and avoid detection. It also automates engagement and outreach.
The guide repeatedly states anti-fingerprinting and shadowban-avoidance goals and provides complete account-creation and engagement workflows.
Mutable Remote Instructions Executed Without Pinning
The guide requires agents to pull account-editable skills live from Wonda and execute each step. It provides no content hash, signature verification, approval boundary, or prompt-injection review before execution.
Remote mutability and direct execution are explicit, while no integrity or trust-control step is documented in the reviewed skill.
Unpinned Global Installation of Executable Packages
The setup directs agents to install the latest npm package globally or trust a Homebrew tap without a version, checksum, or signature verification step. A compromised upstream release would gain local execution.
Both installation commands are explicit and unpinned, and neither path includes an integrity verification step.
Credential Exposure Through Agent Output and Arguments
The guide permits agents to retrieve decrypted passwords and pass passwords in command arguments. Account-creation flows also print passwords in success output, exposing secrets to process listings, shell history, transcripts, or logs.
The reviewed commands and prose explicitly describe decrypted retrieval, password arguments, and password-bearing success output.
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
**LinkedIn account creation:** `wonda linkedin signup` provisions a brand-new LinkedIn account: it m
This section recommends a mobile or residential SOCKS proxy when creating a new social account to avoid platform shadowbans. The proxy is explicitly used for anti-abuse evasion.
`wonda reddit signup` provisions a brand-new Reddit account: it mints a throwaway mailbox (or uses `
This section recommends a mobile or residential SOCKS proxy when creating a new social account to avoid platform shadowbans. The proxy is explicitly used for anti-abuse evasion.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.