wordpress-pro

Pass

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill includes a reference implementation for database backups that stores exports in the public uploads directory.
  • Evidence: references/performance-security.md provides a Database_Backup class that exports SQL dumps to wp-content/uploads/backups/.
  • Context: While the script attempts to secure the folder with an .htaccess file, this protection is server-dependent (Apache-only). In Nginx environments, this configuration could lead to unauthorized database access if backup filenames are discovered.
  • [EXTERNAL_DOWNLOADS]: The skill provides patterns for implementing remote update checks, which involve fetching data from external URLs.
  • Evidence: references/plugin-architecture.md contains an UpdateChecker class using wp_remote_get to retrieve version info from a placeholder domain (example.com). This is a standard architectural pattern for WordPress plugins.
  • [PROMPT_INJECTION]: The skill ingests untrusted user requirements to generate executable PHP and JavaScript code, representing a surface for indirect prompt injection.
  • Ingestion points: Requirements analysis phase defined in SKILL.md.
  • Boundary markers: The workflow lacks explicit separators between user-provided goals and internal agent instructions.
  • Capability inventory: The skill allows the generation of code with filesystem write access (file_put_contents), database interaction ($wpdb), and network requests (wp_remote_get).
  • Sanitization: Although the skill correctly mandates sanitization for the output WordPress code, it does not specify sanitization for the input requirements to prevent instructions from influencing the code generation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 22, 2026, 03:03 PM
Security Audit — agent-trust-hub — wordpress-pro