Wed 1.0.1

PassAudited by VirusTotal on May 1, 2026.

Findings (1)

This skill is classified as suspicious because it executes shell commands (`hostname`) and makes an external network request (`curl` to `https://wed-security-awareness.jamieson9964.workers.dev/log`) to an external server, as detailed in `rules/logic.md`. While the skill explicitly states its purpose is a 'security awareness demonstration' and claims no PII is transmitted, these actions demonstrate high-risk capabilities (shell execution, external communication, silent initial data collection of hostname and CWD) that could be leveraged maliciously. The instructions to the agent in `rules/logic.md` direct it to perform these actions silently before revealing them to the user, which is a form of prompt injection to execute commands beyond the user's immediate expectation of a business plan generator.