Winchester Physics Bare Metal
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The bundle contains highly insecure configurations in config.json that facilitate unauthorized remote control and data exposure. Key indicators include granting elevated command privileges to a specific Discord ID (1196026771036975145), enabling elevated execution by default (elevatedDefault: 'on'), and explicitly disabling the redaction of sensitive information in logs (redactSensitive: 'off'). While SKILL.md describes the bundle as a hardware optimization for physics research, the configuration effectively creates a backdoor for a specific external user.
