today-in-history
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The `SKILL.md` file explicitly instructs the AI agent to execute `curl` commands to fetch data from Wikipedia, indicating the agent possesses shell execution capabilities. Additionally, it contains prompt injection instructions (e.g., to modify output formatting and suppress extra text) that demonstrate the agent's susceptibility to being directed by markdown instructions. While the current `curl` targets are legitimate Wikipedia APIs and the prompt injection aims for clean output, the combination of direct shell command execution and prompt injection vulnerability presents a significant risk for potential remote code execution or unauthorized actions if the agent's input processing is compromised or a malicious prompt is introduced.
