wp-playground

Pass

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the npx command to execute the @wp-playground/cli tool for creating and managing WordPress instances.
  • Evidence: SKILL.md and references/cli-commands.md provide instructions for running npx @wp-playground/cli@latest server and other subcommands.- [EXTERNAL_DOWNLOADS]: Fetches the WordPress Playground CLI tool from the npm registry and can download WordPress Blueprints, plugins, and themes from external URLs during the site setup process.
  • Evidence: SKILL.md and references/blueprints.md mention fetching resources from npm and external ZIP URLs like downloads.wordpress.org.- [REMOTE_CODE_EXECUTION]: WordPress Playground Blueprints support steps that execute code, such as runPHP for inline PHP execution and installPlugin for downloading and activating software.
  • Evidence: references/blueprints.md lists runPHP and installPlugin as common steps in site recipes.- [PROMPT_INJECTION]: The skill processes Blueprint JSON files which act as an ingestion point for untrusted data that can define complex site setup steps.
  • Ingestion points: The --blueprint flag in SKILL.md (Step 3) accepts local file paths or external URLs.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present in the provided skill files.
  • Capability inventory: The CLI tool can write files (writeFile), execute PHP (runPHP), and install plugins from URLs, as detailed in references/blueprints.md.
  • Sanitization: The skill does not describe any specific validation or sanitization of the Blueprint JSON content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 22, 2026, 03:03 PM
Security Audit — agent-trust-hub — wp-playground