wp-interactivity-api
Pass
Audited by Gen Agent Trust Hub on Mar 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: No security issues or malicious patterns were identified. The skill adheres to WordPress development best practices and follows standard API usage patterns.\n- [EXTERNAL_DOWNLOADS]: References official WordPress packages such as @wordpress/scripts and @wordpress/create-block, as well as documentation from developer.wordpress.org. These are well-known and trusted resources within the WordPress development ecosystem.\n- [COMMAND_EXECUTION]: The skill involves the use of bash, node, and WP-CLI for legitimate tasks like asset bundling, project analysis, and E2E testing. These tools are consistent with the skill's stated purpose for a filesystem-based development agent.\n- [PROMPT_INJECTION]: The skill's primary function is to analyze WordPress project files. This surface was evaluated for Indirect Prompt Injection risks:\n
- Ingestion points: Project source code including PHP templates, JavaScript modules, and block.json configuration files (analyzed in SKILL.md).\n
- Boundary markers: Not explicitly defined in the logic, however, the skill focuses on structural analysis and code generation based on user intent.\n
- Capability inventory: The agent utilizes filesystem access, node, bash, and WP-CLI tools as specified in the compatibility section of SKILL.md.\n
- Sanitization: The skill promotes the use of standard WordPress security functions such as esc_html(), wp_create_nonce(), and wp_interactivity_state() to ensure data integrity during client-server communication.
Audit Metadata