wp-perf-fix

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill incorporates explicit instructions to treat all data from the audited site as untrusted, warning the agent to ignore any instructions found within markup or headers. This proactively addresses indirect prompt injection risks.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. The skill uses local scripts for validation and limits network interaction to standard site probing using 'curl'.
  • [DATA_EXFILTRATION]: The skill does not access sensitive user credentials or system files. Data interaction is confined to the specific WordPress site and local project artifacts necessary for the optimization process.
  • [COMMAND_EXECUTION]: Commands are executed within a 'guarded write loop' that mandates manual approval for every change. Validation scripts use secure path resolution to prevent traversal attacks when accessing catalog entries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 11:08 AM
Security Audit — agent-trust-hub — wp-perf-fix