wordpress-plugin-publish
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes official package managers like npm and the WordPress CLI to download the
pressshiputility. These downloads are associated with the vendor's legitimate developer tools and infrastructure.- [COMMAND_EXECUTION]: The skill instructions involve executing local shell commands vianpxandwp-clito perform plugin validation, packaging, and SVN releases. These operations are limited to the plugin directory and are triggered by user-initiated workflows.- [SAFE]: Safety protocols are explicitly integrated into the skill's logic, including instructions to never publish without a dry run, requirements for user confirmation before pushing Git tags, and transparent reporting of validation findings. Handling of WordPress.org SVN credentials follows local security norms, directing users to official password generation pages and storing them locally for tool use.
Audit Metadata