wpscan
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides documentation for executing various shell commands involving powerful security tools like
wpscan,curl, andjq. These commands are designed to interact with external WordPress installations for reconnaissance and vulnerability assessment. - [DATA_EXFILTRATION]: The skill documents the use of
curlandwpscanto perform network requests to external domains. While these are intended for security testing, they involve interacting with non-whitelisted domains to fetch or probe data (e.g., checking for exposed.logor.bakfiles). - [INDIRECT_PROMPT_INJECTION]: The skill outlines workflows where the agent ingests data from external targets (e.g., scan results in JSON format or user lists) and processes it. This creates a surface where malicious content embedded in a WordPress target (like a crafted plugin name or user metadata) could potentially influence the agent's logic or downstream commands.
- Ingestion points:
scan.json,found_users.txt,users.json, and direct outputs fromcurlrequests to WordPress endpoints. - Boundary markers: No boundary markers or 'ignore' instructions are provided to delimit untrusted content.
- Capability inventory: The agent has access to
wpscan,curl,jq, and file-writing capabilities via shell redirection. - Sanitization: No sanitization or validation steps are documented before the ingested data is used in subsequent command-line arguments.
Audit Metadata