wordpress-elementor

Pass

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes WP-CLI (wp @site) to perform administrative tasks on the WordPress database, such as fetching post metadata, updating options, and executing search-and-replace operations on site content.
  • [EXTERNAL_DOWNLOADS]: The skill uses playwright-cli to automate browser interactions with external WordPress administrative panels, which involves network operations to user-specified domains.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface. Ingestion points: Untrusted data is retrieved from the WordPress database via wp post meta get {post_id} _elementor_data (Step 3a and Step 4 of SKILL.md) and processed by the agent. Boundary markers: Absent; there are no explicit delimiters or instructions provided to the agent to disregard instructions embedded in the ingested content. Capability inventory: The skill has access to shell command execution (wp) and browser automation (playwright-cli). Sanitization: Absent; the data retrieved from the site is not sanitized or validated before being used in subsequent operations. This allows for potential exploitation if the site content contains malicious instructions designed to hijack the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 22, 2026, 03:03 PM
Security Audit — agent-trust-hub — wordpress-elementor