rest-api
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive guidance on creating secure WordPress REST API endpoints, specifically emphasizing the mandatory use of
permission_callbackand input sanitization to prevent unauthorized access and injection attacks. - [PROMPT_INJECTION]: No instructions attempting to override agent behavior, bypass safety filters, or extract system prompts were detected.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials, API keys, or sensitive file paths (such as .env or SSH keys) were found within the skill files.
- [DATA_EXFILTRATION]: No unauthorized network operations or patterns involving the transmission of sensitive data to external domains were identified.
- [OBFUSCATION]: There is no evidence of Base64 encoding, hex escapes, zero-width characters, or homoglyph attacks intended to hide malicious content.
- [REMOTE_CODE_EXECUTION]: The skill does not include any patterns for downloading and executing remote scripts or performing unsafe dynamic code execution.
Audit Metadata