wordpress-pro
Pass
Audited by Gen Agent Trust Hub on Mar 22, 2026
Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill includes a reference implementation for database backups that stores exports in the public uploads directory.
- Evidence:
references/performance-security.mdprovides aDatabase_Backupclass that exports SQL dumps towp-content/uploads/backups/. - Context: While the script attempts to secure the folder with an
.htaccessfile, this protection is server-dependent (Apache-only). In Nginx environments, this configuration could lead to unauthorized database access if backup filenames are discovered. - [EXTERNAL_DOWNLOADS]: The skill provides patterns for implementing remote update checks, which involve fetching data from external URLs.
- Evidence:
references/plugin-architecture.mdcontains anUpdateCheckerclass usingwp_remote_getto retrieve version info from a placeholder domain (example.com). This is a standard architectural pattern for WordPress plugins. - [PROMPT_INJECTION]: The skill ingests untrusted user requirements to generate executable PHP and JavaScript code, representing a surface for indirect prompt injection.
- Ingestion points: Requirements analysis phase defined in
SKILL.md. - Boundary markers: The workflow lacks explicit separators between user-provided goals and internal agent instructions.
- Capability inventory: The skill allows the generation of code with filesystem write access (
file_put_contents), database interaction ($wpdb), and network requests (wp_remote_get). - Sanitization: Although the skill correctly mandates sanitization for the output WordPress code, it does not specify sanitization for the input requirements to prevent instructions from influencing the code generation process.
Audit Metadata