php-wordpress-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured guidelines for auditing WordPress-specific security mechanisms such as nonces, capabilities, and AJAX handlers. It does not contain any malicious payloads or instructions to bypass safety filters.
  • [SAFE]: No hardcoded credentials, suspicious network operations, or unauthorized file access patterns were identified. The tool operates on user-provided local source paths to generate audit reports.
  • [SAFE]: The skill does not download or execute remote code, nor does it include any obfuscated text, hidden URLs, or persistence mechanisms.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it is designed to ingest and analyze untrusted external data (third-party WordPress source code). However, this is inherent to its primary function as a security auditor, and the risk is considered low as the skill does not grant the agent high-privilege capabilities triggered by the data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:59 AM
Security Audit — agent-trust-hub — php-wordpress-audit