wp-interactivity-api

Pass

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: No security issues or malicious patterns were identified. The skill adheres to WordPress development best practices and follows standard API usage patterns.\n- [EXTERNAL_DOWNLOADS]: References official WordPress packages such as @wordpress/scripts and @wordpress/create-block, as well as documentation from developer.wordpress.org. These are well-known and trusted resources within the WordPress development ecosystem.\n- [COMMAND_EXECUTION]: The skill involves the use of bash, node, and WP-CLI for legitimate tasks like asset bundling, project analysis, and E2E testing. These tools are consistent with the skill's stated purpose for a filesystem-based development agent.\n- [PROMPT_INJECTION]: The skill's primary function is to analyze WordPress project files. This surface was evaluated for Indirect Prompt Injection risks:\n
  • Ingestion points: Project source code including PHP templates, JavaScript modules, and block.json configuration files (analyzed in SKILL.md).\n
  • Boundary markers: Not explicitly defined in the logic, however, the skill focuses on structural analysis and code generation based on user intent.\n
  • Capability inventory: The agent utilizes filesystem access, node, bash, and WP-CLI tools as specified in the compatibility section of SKILL.md.\n
  • Sanitization: The skill promotes the use of standard WordPress security functions such as esc_html(), wp_create_nonce(), and wp_interactivity_state() to ensure data integrity during client-server communication.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 22, 2026, 03:03 PM
Security Audit — agent-trust-hub — wp-interactivity-api