wordpress-plugin-publish

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes official package managers like npm and the WordPress CLI to download the pressship utility. These downloads are associated with the vendor's legitimate developer tools and infrastructure.- [COMMAND_EXECUTION]: The skill instructions involve executing local shell commands via npx and wp-cli to perform plugin validation, packaging, and SVN releases. These operations are limited to the plugin directory and are triggered by user-initiated workflows.- [SAFE]: Safety protocols are explicitly integrated into the skill's logic, including instructions to never publish without a dry run, requirements for user confirmation before pushing Git tags, and transparent reporting of validation findings. Handling of WordPress.org SVN credentials follows local security norms, directing users to official password generation pages and storing them locally for tool use.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 04:31 PM
Security Audit — agent-trust-hub — wordpress-plugin-publish