generating-patterns

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses strong instructional language such as '⛔ Cardinal rule' and 'NEVER synthesized' to enforce strict data fidelity (verbatim copy) during the replica generation process. This is a legitimate operational constraint for its specific use case and does not attempt to bypass AI safety filters.
  • [COMMAND_EXECUTION]: The instructions explicitly prohibit the use of raw PHP or script tags (e.g., 'wp:html is banned project-wide', 'treats ANY other <?php ... as injection'). It only permits two specific, safe PHP forms for theme headers and asset URLs.
  • [DATA_EXFILTRATION]: There are no network-capable commands like curl or wget. The instructions specifically warn against curling CDN URLs and instead mandate using local theme assets or pre-uploaded WordPress media library URLs.
  • [EXTERNAL_DOWNLOADS]: The skill mentions external services like Shopify, Wix, and various review widgets (Okendo, Yotpo, etc.), but only in the context of identifying them for stubbing or static extraction. No remote code execution or untrusted package installation occurs.
  • [REMOTE_CODE_EXECUTION]: The skill is configured with disable-model-invocation: true, which prevents the agent from calling external tools during its execution of these specific guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 09:43 PM
Security Audit — agent-trust-hub — generating-patterns