php-wordpress-audit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured guidelines for auditing WordPress-specific security mechanisms such as nonces, capabilities, and AJAX handlers. It does not contain any malicious payloads or instructions to bypass safety filters.
- [SAFE]: No hardcoded credentials, suspicious network operations, or unauthorized file access patterns were identified. The tool operates on user-provided local source paths to generate audit reports.
- [SAFE]: The skill does not download or execute remote code, nor does it include any obfuscated text, hidden URLs, or persistence mechanisms.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it is designed to ingest and analyze untrusted external data (third-party WordPress source code). However, this is inherent to its primary function as a security auditor, and the risk is considered low as the skill does not grant the agent high-privilege capabilities triggered by the data.
Audit Metadata