Trust Assessment
wacli received a trust score of 40/100, placing it in the Untrusted category. This skill has significant security findings that require attention before use in production.
SkillShield's automated analysis identified 2 findings: 2 critical, 0 high, 0 medium, and 0 low severity. Key findings include Obfuscated execution: base64 decode to shell, Obfuscated Remote Code Execution during MacOS installation.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 13, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings2
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| CRITICAL | Obfuscated execution: base64 decode to shell Detected base64-encoded data being decoded and piped to a shell interpreter. This is a common obfuscation technique. Decode and inspect the base64 content before execution. | Static | skills/sakaen736jih/wacli-eco/SKILL.md:10 | |
| CRITICAL | Obfuscated Remote Code Execution during MacOS installation The skill's installation instructions for MacOS include a command that decodes a base64 string and pipes it directly to `bash`. The decoded string executes a `curl` command to download a script from an untrusted IP address (`http://91.92.242.30/tmjvje9itarrd3txw`) and then executes that downloaded script. This allows arbitrary code execution from an external, potentially malicious, source during the skill's setup process, posing a severe supply chain risk. Remove the obfuscated remote script execution command. Provide clear, auditable installation instructions, preferably using package managers or direct downloads from trusted sources with checksum verification. If `OpenClawProvider` is truly required, its installation should be documented transparently and securely, ideally from a trusted package repository or a verified source. | LLM | SKILL.md:10 |
Scan History
Embed Code
[](https://skillshield.io/report/250c3c0dec53dff4)
Powered by SkillShield