Jrb Remote Site Api Skill Repo

PassAudited by VirusTotal on May 11, 2026.

Findings (1)

The skill is classified as suspicious due to its extremely broad and high-risk capabilities, particularly the 'Plugin & Theme Management' functions described in SKILL.md. The ability to install plugins and themes from arbitrary URLs on a target WordPress site presents a critical Remote Code Execution (RCE) vulnerability. While these capabilities might be intended for legitimate administrative tasks, they can be easily abused through prompt injection or a compromised agent to install malicious software, leading to full compromise of the target WordPress site. There is no direct evidence of intentional malicious behavior by the skill itself (e.g., exfiltration from the agent's host), but the inherent power granted makes it a significant security risk.