wordpress-router

Pass

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Node.js triage script to analyze the repository structure and identify project types.
  • [COMMAND_EXECUTION]: Instructions recommend running standard repository commands for linting, testing, and building based on the triage output.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from repository configuration files to determine the routing workflow, presenting an indirect prompt injection surface.
  • Ingestion points: Repository files such as package.json, composer.json, and style.css.
  • Boundary markers: None present in the instruction files.
  • Capability inventory: Execution of a local Node.js triage script and suggested repository build/test commands.
  • Sanitization: No explicit sanitization or validation logic is defined for the ingested file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 22, 2026, 03:03 PM
Security Audit — agent-trust-hub — wordpress-router