Farmos Weather
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill instructs the AI agent to interact with other modules (e.g., `farmos-tasks`, `farmos-observations`) and explicitly suggests creating tasks based on weather conditions, as seen in `SKILL.md`. While intended for legitimate integration, this cross-module action triggering represents a powerful capability that could be leveraged in a vulnerability chain if other modules are compromised. Additionally, the API base `http://100.102.77.110:8012` points to a private IP address, indicating the agent has access to internal network resources, which elevates its privilege level beyond accessing public APIs. These capabilities, though not inherently malicious in this context, introduce a higher risk profile.
