match-section

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Detailed analysis of the skill's instructions confirms it is designed for a specific developer workflow involving WordPress site replication. No obfuscation, data exfiltration, or malicious commands were detected.\n- [COMMAND_EXECUTION]: The skill uses local commands including studio wp for site management and ImageMagick utilities (identify, convert) for image manipulation. These operations are essential for its functional goals and are conducted within a local development context.\n- [EXTERNAL_DOWNLOADS]: While the skill uses Playwright to navigate to URLs, these are restricted to local preview endpoints and source screenshots provided by the orchestrator. No untrusted code or remote dependencies are fetched or executed.\n- [PROMPT_INJECTION]: The skill ingests site data and styledHtml for visual analysis. While this is external data, it is used for attribute extraction and is not interpolated into the prompt in a way that allows for instruction override.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 09:44 PM
Security Audit — agent-trust-hub — match-section