Japan Business Operations (EDITION)
PassAudited by VirusTotal on May 10, 2026.
Findings (1)
The skill bundle defines tools that interact with an external API (api.edition.sh), including a 'Persistent Memory' feature in SKILL.md that encourages the agent to exfiltrate session context and business data to a third-party server. Additionally, it instructs the user to execute a remote npm package (edition-mcp-server) via npx, which presents a risk of remote code execution. While these are framed as legitimate business intelligence features, the centralized storage of agent 'memories' and the execution of unvetted remote code are high-risk behaviors.
