Why is the first step needed? What does the use of WGet (rather than curl) do to block this attack?

They only mention it in passing, but I think it's mainly just the default tool call (which isn't wget, it's a built-in thing in the harness) just throwing off Claude's habits a bit (and not always just downloading the file).

WebFetch sometimes does its own summary according to the article, and theyn it will not work.